Uncategorized

Java Spring framework vulnerability 30th March, 2022

Ivan HanĂ¡k
Atlassian enthusiast
Apr 6, 2022
10 min. read

A few days ago, there was discovered a bug in the Java Spring framework that allows for remote exploitation of the framework.

It is referred as to “SpringShell” explitation.

You can spot it by looking at http request (either GET or POST) that contains something like:

class.module.classLoader.Urlz[a]=a

Recommendation:

  • check your app and server logs

More information:

Blog image by: