Spring4shell exploit attempts have been detected by SANS.

The Spring4Shell remote code execution vulnerability in the Spring framework for Java has been evaluated as critical, with a 9.8 out of 10 score and patches provided, following disagreement among security researchers about its importance.

SANS Internet Storm Centre security researchers claim they’ve seen attempts to launch web shells on their Apache Tomcat honeypot systems this week, indicating that attackers are looking for vulnerable applications to exploit.

A publicly available exploit attempts to write a file containing code to construct a simple web shell accessible from a browser to the root directory of a susceptible application.

Version 9 of the Java Development Kit is required, as well as Apache Tomcat operating as a servlet container.

The vulnerability also requires Spring frameworks 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and earlier.

Vulnerable code must also be packaged as a compressed WAR web application archive that includes the spring-webmvc and spring-webflux dependencies.

Although applications delivered as Java archives are not vulnerable, the Spring project advises that the problem is more generic in nature and that there may be other ways to exploit it.

Spring4Shell could allow remote code execution, according to the United States Computer Emergency Response Team at Carnegie Mellon University.

Akshara Krishnan
Akshara Krishnan
Akshara Krishnan is passionate content and copywriter, who is highly interested and competent in the fields of digital marketing and supply chain management. She is an avid reader who enjoys books on self-help and psychology, and actively partakes in classical singing.

Similar Articles

Comments

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular