Toutes les vulnérabilités
CRITICALInfraexploited in the wildcurated

CVE-2022-22965

Maven · org.springframework.boot:spring-boot-starter-webflux

Résumé

A remote code execution flaw in the Spring Framework's data-binding mechanism. On JDK 9 and later, an unauthenticated attacker can manipulate request parameters to access the ClassLoader and write a malicious JSP web shell to disk, achieving RCE. Exploitation specifically targets Spring MVC and WebFlux applications deployed as WAR files on Apache Tomcat. It was mass-exploited within days of disclosure to deploy cryptocurrency miners and the Mirai botnet.

Références

Vulnérabilités liées

Tout Infra →