Spring4Shell

lore

securityprogramming

A 2022 remote code execution flaw in the Spring Framework for Java.

Spring4Shell let attackers achieve remote code execution through data binding in certain Spring configurations. Coming shortly after Log4Shell, it renewed attention on the risk carried by ubiquitous Java dependencies.

Also known as: Spring4Shell, CVE-2022-22965

Sources

  • CVE-2022-22965 (2022)

All glossary entries