All vulnerabilities
CRITICALInfraexploited in the wildcurated

CVE-2022-22965

Maven · org.springframework.boot:spring-boot-starter-webflux

Summary

A remote code execution flaw in the Spring Framework's data-binding mechanism. On JDK 9 and later, an unauthenticated attacker can manipulate request parameters to access the ClassLoader and write a malicious JSP web shell to disk, achieving RCE. Exploitation specifically targets Spring MVC and WebFlux applications deployed as WAR files on Apache Tomcat. It was mass-exploited within days of disclosure to deploy cryptocurrency miners and the Mirai botnet.

References

Related vulnerabilities

All Infra →