Site icon Auspreneur

Spring4shell exploit attempts have been detected by SANS.

Australia

The Spring4Shell remote code execution vulnerability in the Spring framework for Java has been evaluated as critical, with a 9.8 out of 10 score and patches provided, following disagreement among security researchers about its importance.

SANS Internet Storm Centre security researchers claim they’ve seen attempts to launch web shells on their Apache Tomcat honeypot systems this week, indicating that attackers are looking for vulnerable applications to exploit.

A publicly available exploit attempts to write a file containing code to construct a simple web shell accessible from a browser to the root directory of a susceptible application.

Version 9 of the Java Development Kit is required, as well as Apache Tomcat operating as a servlet container.

The vulnerability also requires Spring frameworks 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and earlier.

Vulnerable code must also be packaged as a compressed WAR web application archive that includes the spring-webmvc and spring-webflux dependencies.

Although applications delivered as Java archives are not vulnerable, the Spring project advises that the problem is more generic in nature and that there may be other ways to exploit it.

Spring4Shell could allow remote code execution, according to the United States Computer Emergency Response Team at Carnegie Mellon University.

Exit mobile version