CVE-2022-22965

CRITICAL KEV RANSOMWARE NUCLEI LAB

Vmware Spring Framework < 5.2.20 - Code Injection

Title source: rule

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Exploits (119)

nomisec WORKING POC 374 stars
by BobTheShoplifter · remote
https://github.com/BobTheShoplifter/Spring4Shell-POC
nomisec WORKING POC 325 stars
by reznok · remote
https://github.com/reznok/Spring4Shell-POC
nomisec SCANNER 154 stars
by tpt11fb · poc
https://github.com/tpt11fb/SpringVulScan
nomisec WORKING POC 130 stars
by TheGejr · remote
https://github.com/TheGejr/SpringShell
nomisec WORKING POC 102 stars
by zangcc · poc
https://github.com/zangcc/CVE-2022-22965-rexbb
nomisec SCANNER 101 stars
by alt3kx · remote
https://github.com/alt3kx/CVE-2022-22965
nomisec WORKING POC 73 stars
by SecNN · poc
https://github.com/SecNN/SpringFramework_CVE-2022-22965_RCE
nomisec WORKING POC 63 stars
by 4nth0ny1130 · remote
https://github.com/4nth0ny1130/spring4shell_behinder
nomisec WORKING POC 50 stars
by Mr-xn · poc
https://github.com/Mr-xn/spring-core-rce
nomisec WORKING POC 44 stars
by colincowie · remote
https://github.com/colincowie/Safer_PoC_CVE-2022-22965
nomisec WORKING POC 44 stars
by FourCoreLabs · poc
https://github.com/FourCoreLabs/spring4shell-exploit-poc
nomisec WORKING POC 41 stars
by tangxiaofeng7 · poc
https://github.com/tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce
nomisec WORKING POC 31 stars
by Kirill89 · remote
https://github.com/Kirill89/CVE-2022-22965-PoC
nomisec WORKING POC 28 stars
by k3rwin · poc
https://github.com/k3rwin/spring-core-rce
nomisec WORKING POC 26 stars
by liangyueliangyue · poc
https://github.com/liangyueliangyue/spring-core-rce
nomisec WORKING POC 23 stars
by p1ckzi · poc
https://github.com/p1ckzi/CVE-2022-22965
nomisec WORKING POC 19 stars
by DDuarte · remote
https://github.com/DDuarte/springshell-rce-poc
nomisec WORKING POC 17 stars
by alt3kx · poc
https://github.com/alt3kx/CVE-2022-22965_PoC
nomisec WORKING POC 17 stars
by Bouquets-ai · poc
https://github.com/Bouquets-ai/CVE-2022-22965-GUItools
nomisec WORKING POC 16 stars
by itsecurityco · remote
https://github.com/itsecurityco/CVE-2022-22965
nomisec WORKING POC 16 stars
by wjl110 · poc
https://github.com/wjl110/CVE-2022-22965_Spring_Core_RCE
nomisec WORKING POC 14 stars
by me2nuk · remote
https://github.com/me2nuk/CVE-2022-22965
nomisec WORKING POC 13 stars
by viniciuspereiras · remote
https://github.com/viniciuspereiras/CVE-2022-22965-poc
nomisec SCANNER 12 stars
by fracturelabs · poc
https://github.com/fracturelabs/go-scan-spring
nomisec WORKING POC 12 stars
by zer0yu · poc
https://github.com/zer0yu/CVE-2022-22965
nomisec SCANNER 8 stars
by gpiechnik2 · poc
https://github.com/gpiechnik2/nmap-spring4shell
nomisec WORKING POC 7 stars
by sunnyvale-it · remote
https://github.com/sunnyvale-it/CVE-2022-22965-PoC
nomisec WORKING POC 7 stars
by Wrin9 · remote
https://github.com/Wrin9/CVE-2022-22965
nomisec WORKING POC 6 stars
by GuayoyoCyber · poc
https://github.com/GuayoyoCyber/CVE-2022-22965
nomisec WORKING POC 6 stars
by wikiZ · poc
https://github.com/wikiZ/springboot_CVE-2022-22965
github STUB 5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/spring-CVE-2022-22965
nomisec WORKING POC 5 stars
by mariomamo · remote
https://github.com/mariomamo/CVE-2022-22965
nomisec WORKING POC 4 stars
by iloveflag · remote
https://github.com/iloveflag/Fast-CVE-2022-22965
nomisec SCANNER 4 stars
by Loneyers · poc
https://github.com/Loneyers/Spring4Shell
nomisec WORKING POC 4 stars
by nu0l · remote
https://github.com/nu0l/CVE-2022-22965
nomisec WORKING POC 4 stars
by wshon · poc
https://github.com/wshon/spring-framework-rce
nomisec WORKING POC 3 stars
by 0xrobiul · remote
https://github.com/0xrobiul/CVE-2022-22965
nomisec WORKING POC 3 stars
by BKLockly · remote
https://github.com/BKLockly/CVE-2022-22965
nomisec WORKING POC 3 stars
by likewhite · remote
https://github.com/likewhite/CVE-2022-22965
nomisec WRITEUP 3 stars
by khidottrivi · poc
https://github.com/khidottrivi/CVE-2022-22965
nomisec WORKING POC 3 stars
by CalumHutton · poc
https://github.com/CalumHutton/CVE-2022-22965-PoC_Payara
nomisec WORKING POC 3 stars
by netcode · remote
https://github.com/netcode/Spring4shell-CVE-2022-22965-POC
nomisec WORKING POC 2 stars
by bL34cHig0 · remote
https://github.com/bL34cHig0/Telstra-Cybersecurity-Virtual-Experience-
nomisec WORKING POC 2 stars
by jakabakos · remote
https://github.com/jakabakos/CVE-2022-22965-Spring4Shell
nomisec WORKING POC 2 stars
by D1mang · poc
https://github.com/D1mang/Spring4Shell-CVE-2022-22965
nomisec WORKING POC 2 stars
by datawiza-inc · poc
https://github.com/datawiza-inc/spring-rec-demo
nomisec WORKING POC 2 stars
by fracturelabs · poc
https://github.com/fracturelabs/spring4shell_victim
nomisec WRITEUP 2 stars
by irgoncalves · poc
https://github.com/irgoncalves/irule-cve-2022-22965
nomisec WORKING POC 2 stars
by LudovicPatho · poc
https://github.com/LudovicPatho/CVE-2022-22965_Spring4Shell
nomisec WORKING POC 2 stars
by twseptian · poc
https://github.com/twseptian/cve-2022-22965
nomisec WORKING POC 2 stars
by rwincey · poc
https://github.com/rwincey/spring4shell-CVE-2022-22965
gitlab WORKING POC 1 stars
by chiangyaw · remote
https://gitlab.com/chiangyaw/Spring4Shell-POC
nomisec WORKING POC 1 stars
by mylo-2001 · remote
https://github.com/mylo-2001/GhostStrike
nomisec WORKING POC 1 stars
by salo-404 · poc
https://github.com/salo-404/firewall
nomisec WORKING POC 1 stars
by cxzero · remote
https://github.com/cxzero/CVE-2022-22965-spring4shell
nomisec STUB 1 stars
by gokul-ramesh · poc
https://github.com/gokul-ramesh/Spring4Shell-PoC-exploit
nomisec WORKING POC 1 stars
by clemoregan · remote
https://github.com/clemoregan/SSE4-CVE-2022-22965
nomisec WORKING POC 1 stars
by c4mx · poc
https://github.com/c4mx/CVE-2022-22965_PoC
nomisec WRITEUP 1 stars
by Snip3R69 · poc
https://github.com/Snip3R69/spring-shell-vuln
nomisec WORKING POC 1 stars
by daniel0x00 · poc
https://github.com/daniel0x00/Invoke-CVE-2022-22965-SafeCheck
nomisec WRITEUP 1 stars
by helsecert · poc
https://github.com/helsecert/CVE-2022-22965
nomisec WORKING POC 1 stars
by Joe1sn · poc
https://github.com/Joe1sn/CVE-2022-22965
nomisec WORKING POC 1 stars
by lcarea · poc
https://github.com/lcarea/CVE-2022-22965
nomisec WORKING POC
by glory903-devsecops · poc
https://github.com/glory903-devsecops/CVE-2022-22965
nomisec WORKING POC
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2022-22965
nomisec WORKING POC
by 0xAshwesker · poc
https://github.com/0xAshwesker/CVE-2022-22965
nomisec WORKING POC
by zaryouhashraf · poc
https://github.com/zaryouhashraf/CVE-2022-22965
gitlab WORKING POC
by pokoyo.bughunter · poc
https://gitlab.com/pokoyo.bughunter/spring4shell-vulnerability-poc-app
gitlab WORKING POC
by milo2012 · remote
https://gitlab.com/milo2012/cve-2022-22965
gitlab WORKING POC
by pausersg · poc
https://gitlab.com/pausersg/Spring4Shell-POC
nomisec WORKING POC
by aditidutta696-dev · poc
https://github.com/aditidutta696-dev/Spring4Shell-CVE-2022-22965-Exploitation-Attempt
nomisec WORKING POC
by suyash-R-K · poc
https://github.com/suyash-R-K/dfir-malware-investigation
nomisec WRITEUP
by Shakur1314 · poc
https://github.com/Shakur1314/CVE-2022-22965-Spring4Shell-Security-Operations-Analysis
nomisec WORKING POC
by nhattanhh · remote
https://github.com/nhattanhh/CVE-2022-22965
nomisec WORKING POC
by dbwlsdnr95 · poc
https://github.com/dbwlsdnr95/CVE-2022-22965
nomisec WORKING POC
by xenosf · remote
https://github.com/xenosf/CS4239-Spring4Shell-POC
nomisec WORKING POC
by NickoPS87 · poc
https://github.com/NickoPS87/Spring4Shell-Python-Firewall-POC
nomisec STUB
by shoucheng3 · poc
https://github.com/shoucheng3/spring-projects__spring-framework_CVE-2022-22965_5-2-19-RELEASE
github WRITEUP
by OscarYR · poc
https://github.com/OscarYR/CVE_Reproduction/tree/main/Spring4Shell/CVE-2022-22965.md
nomisec WORKING POC
by Nosie12 · poc
https://github.com/Nosie12/fire-wall-server
nomisec WORKING POC
by osungjinwoo · remote
https://github.com/osungjinwoo/CVE-2022-22965
nomisec WRITEUP
by brunoh6 · poc
https://github.com/brunoh6/web-threat-mitigation
nomisec WORKING POC
by jashan-lefty · poc
https://github.com/jashan-lefty/Spring4Shell
nomisec WORKING POC
by Aur3ns · poc
https://github.com/Aur3ns/Block-Spring4Shell
nomisec WORKING POC
by guigui237 · poc
https://github.com/guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
nomisec WORKING POC
by LucasPDiniz · remote
https://github.com/LucasPDiniz/CVE-2022-22965
nomisec WORKING POC
by xsxtw · remote
https://github.com/xsxtw/SpringFramework_CVE-2022-22965_RCE
nomisec WORKING POC
by ESSAFAR · poc
https://github.com/ESSAFAR/Firewall-Rules
nomisec WORKING POC
by sohamsharma966 · remote
https://github.com/sohamsharma966/Spring4Shell-CVE-2022-22965
nomisec WORKING POC
by dbgee · remote
https://github.com/dbgee/Spring4Shell
nomisec WORKING POC
by c33dd · remote
https://github.com/c33dd/CVE-2022-22965
nomisec WORKING POC
by ajith737 · remote
https://github.com/ajith737/Spring4Shell-CVE-2022-22965-POC
nomisec WORKING POC
by devengpk · remote
https://github.com/devengpk/CVE-2022-22965
nomisec WRITEUP
by Enokiy · poc
https://github.com/Enokiy/spring-RCE-CVE-2022-22965
nomisec STUB
by snicoll-scratches · poc
https://github.com/snicoll-scratches/spring-boot-cve-2022-22965
nomisec WORKING POC
by Omaraitbenhaddi · remote
https://github.com/Omaraitbenhaddi/-Spring4Shell-CVE-2022-22965-
nomisec WORKING POC
by te5t321 · poc
https://github.com/te5t321/Spring4Shell-CVE-2022-22965.py
nomisec STUB
by fransvanbuul · poc
https://github.com/fransvanbuul/CVE-2022-22965-susceptibility
nomisec WORKING POC
by t3amj3ff · poc
https://github.com/t3amj3ff/Spring4ShellPoC
nomisec WORKING POC
by luoqianlin · poc
https://github.com/luoqianlin/CVE-2022-22965
nomisec WORKING POC
by 0xr1l3s · poc
https://github.com/0xr1l3s/CVE-2022-22965
nomisec WORKING POC
by mwojterski · poc
https://github.com/mwojterski/cve-2022-22965
nomisec SCANNER
by mebibite · poc
https://github.com/mebibite/springhound
vulncheck_xdb WORKING POC
remote
https://github.com/AabyssZG/SpringBoot-Scan
vulncheck_xdb WORKING POC
remote
https://github.com/W01fh4cker/Serein
vulncheck_xdb SCANNER
remote
https://github.com/tangxiaofeng7/CVE-2022-22965-Spring-CachedintrospectionResults-Rce
vulncheck_xdb WORKING POC
remote
https://github.com/cybersecurityworks553/spring4shell-exploit
vulncheck_xdb WORKING POC
remote
https://github.com/jbaines-r7/spring4shell_vulnapp
vulncheck_xdb WORKING POC
remote
https://github.com/ckkok/spring4shell-poc
vulncheck_xdb WORKING POC
remote
https://github.com/VAnD4L/spring4shell
vulncheck_xdb WORKING POC
remote
https://github.com/craig/SpringCore0day
vulncheck_xdb WORKING POC
remote
https://github.com/hktalent/spring-spel-0day-poc
metasploit WORKING POC MANUAL
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/spring_framework_rce_spring4shell.rb

Nuclei Templates (2)

Spring Framework RCE via Data Binding on JDK 9+
CRITICALby DhiyaneshDK,ritikchaddha
Spring - Remote Code Execution
CRITICALby justmumu,arall,dhiyaneshDK,akincibor

Scores

CVSS v3 9.8
EPSS 0.9443
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull tomcat:9.0.60-jre11-openjdk-slim-buster
docker pull lunasec/tomcat-9.0.59-jdk11
docker pull tomcat:8.5-jdk11-openjdk-slim-buster
docker pull tomcat:9
docker pull s4sgoof:orig
+11 more images
+106 more repos

Details

CISA KEV 2022-04-04
VulnCheck KEV 2022-04-04
InTheWild.io 2022-03-31
ENISA EUVD EUVD-2022-1283
Ransomware Use Confirmed
CWE
CWE-94
Status published
Products (50)
cisco/cx_cloud_agent < 2.1.0
oracle/commerce_platform 11.3.2
oracle/communications_cloud_native_core_automated_test_suite 1.9.0
oracle/communications_cloud_native_core_automated_test_suite 22.1.0
oracle/communications_cloud_native_core_binding_support_function 22.1.3
oracle/communications_cloud_native_core_console 1.9.0
oracle/communications_cloud_native_core_console 22.1.0
oracle/communications_cloud_native_core_network_exposure_function 22.1.0
oracle/communications_cloud_native_core_network_function_cloud_native_environment 1.10.0
oracle/communications_cloud_native_core_network_function_cloud_native_environment 22.1.0
... and 40 more
Published Apr 01, 2022
KEV Added Apr 04, 2022
Tracked Since Feb 18, 2026