Skip to content
Charm Nail Spa

Charm Nail Spa

Power Beyond Expectation

Primary Menu
  • Computer & Technology
  • internet marketing
  • Web Design
  • Technology
  • computer
  • Business
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
  • Home
  • Explaining Spring4Shell: The Internet security disaster that wasn’t
  • internet

Explaining Spring4Shell: The Internet security disaster that wasn’t

Lisa H. Shelton April 6, 2022 5 minutes read

[ad_1]

Explaining Spring4Shell: The Internet security disaster that wasn’t

Getty Images

Hype and hyperbole were on full display this week as the security world reacted to reports of yet another Log4Shell. The vulnerability came to light in December and is arguably one of the gravest Internet threats in years. Christened Spring4Shell—the new code-execution bug is in the widely used Spring Java framework—the threat quickly set the security world on fire as researchers scrambled to assess its severity.

One of the first posts to report on the flaw was on tech news site Cyber Kendra, which warned of severe damage the flaw might cause to “tonnes of applications” and claimed that the bug “can ruin the Internet.” Almost immediately, security companies, many of them pushing snake oil, were falling all over themselves to warn of the imminent danger we would all face. And all of that before a vulnerability tracking designation or advisory from Spring maintainers was even available.

Table of Contents

Toggle
  • All aboard
  • SpringShell, not Spring4Shell
  • About the Author
    • Lisa H. Shelton

All aboard

The hype train started on Wednesday after a researcher published a proof-of-concept exploit that could remotely install a web-based remote control backdoor known as a web shell on a vulnerable system. People were understandably concerned because the vulnerability was so easy to exploit and was in a framework that powers a massive number of websites and apps.

The vulnerability resides in two Spring products: Spring MVC and Spring WebFlux, which allow developers to write and test apps. The flaw results from changes introduced in JDK9 that resurrected a decade-old vulnerability tracked as CVE-2010-1622. Given the abundance of systems that combine the Spring framework and JDK9 or later, no wonder people were concerned, particularly since exploit code was already in the wild (the initial leaker quickly took down the PoC, but by then it was too late.)

Advertisement

On Thursday, the flaw finally received the designation CVE-2022-22965. Security defenders also got a much more nuanced description of the threat it posed. The leaked code, Spring maintainers said, ran only when a Spring-developed app ran on top of Apache Tomcat and then only when the app is deployed as a file type known as a WAR, short for web archive.

“If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit,” the Spring maintainers wrote. “However, the nature of the vulnerability is more general, and there may be other ways to exploit it.”

While the post left open the possibility that the PoC exploit could be improved to work against other configurations, no one has unearthed a variation that does, at least for now.

“It’s a thing that developers should fix, if they’re using an affected version,” Will Dormann, a vulnerability analyst at CERT, said in a private message. “But we’re still in the boat of not knowing of a single application out there that is exploitable.”

On Twitter, Dormann took Cyber Kendra to task.

“Ways that Cyber Kendra made this worse for everyone,” he wrote. “1) Sensational blog post indicating that this is going to ruin the internet (red flag!) 2) Linking to a git commit about deserialization that has absolutely nothing to do with the issue demonstrated by the original party.”

Ways that Cyber Kendra made this worse for everyone:
1) Sensational blog post indicating that this is going to ruin the internet (red flag!).
2) Linking to a git commit about deserialization that has absolutely nothing to do with the issue demonstrated by the original party. pic.twitter.com/91MAfL7K4r

— Will Dormann (@wdormann) March 31, 2022

A Cyber Kendra representative didn’t respond to an email seeking comment. In fairness, the line about ruining the internet was later struck through.

Advertisement

SpringShell, not Spring4Shell

Sadly, even though there’s consensus that, at least for now, the vulnerability doesn’t pose anything near the threat of Log4Shell, the Spring4Shell name has largely stuck. That’s will likely mislead some about its severity. Going forward, Ars will refer to it by its more appropriate name, SpringShell.

Several researchers say they have detected scans in the wild that use the leaked CVE-2022-22965 PoC or an exploit very much like it. It’s not unusual for researchers to benignly test servers to understand how prevalent a new vulnerability is. Slightly more concerning is a report on Friday in which researchers from Netlab 360 said a variant of Mirai—malware that can wrangle thousands of IoT devices and produce crippling denial-of-service attacks—“has won the race as the first botnet that adopted this vulnerability.”

To make matters more confusing, a separate code-execution vulnerability surfaced last week that affects Spring Cloud Function, which allows developers to easily decouple the business logic in an app from a specific runtime. The flaw, tracked as CVE-2022-22963, resides in the Spring Expression Language, typically known as SpEL.

Both vulnerabilities are potentially serious and should by no means be ignored. That means updating the Spring Framework to 5.3.18 or 5.2.20, and out of an abundance of caution also upgrading to Tomcat 10.0.20, 9.0.62, or 8.5.78. Those using the Spring Cloud Function should update to either 3.1.7 or 3.2.3.

For people who aren’t sure if their apps are vulnerable to CVE-2022-22965, researchers at security firm Randori have released a simple, non-malicious script that can check.

So by all means, test and patch like there’s no tomorrow, but don’t believe the hype.



[ad_2]

Source link

About the Author

Lisa H. Shelton

Administrator

Visit Website View All Posts

Post navigation

Previous: Winning the tech talent war
Next: How Digital Marketing Mogul Cameron Shu Turned His Failure Into Success

Related News

Revolutionizing Tomorrow: The AI-Powered Future of Internet Technology
  • internet

Revolutionizing Tomorrow: The AI-Powered Future of Internet Technology

Lisa H. Shelton September 3, 2026
The Future of Internet Technology: Beyond the Cloud
  • internet

The Future of Internet Technology: Beyond the Cloud

Lisa H. Shelton September 1, 2026
The Internet: A Double-Edged Sword of Connection and Chaos
  • internet

The Internet: A Double-Edged Sword of Connection and Chaos

Lisa H. Shelton August 30, 2026
September 2026
M T W T F S S
 123456
78910111213
14151617181920
21222324252627
282930  
« Aug    

Archives

  • September 2026
  • August 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • September 2025
  • May 2025
  • April 2025
  • March 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • March 2020
  • February 2020
  • November 2018
  • October 2018
  • January 2017

Categories

  • Business
  • computer
  • Computer & Technology
  • internet
  • internet marketing
  • Technology
  • Web Design

Recent Posts

  • The Future of Computing: Unlocking the Power of Quantum AI
  • The Future Unplugged: How AI is Redefining Human Creativity
  • Future-Proofing Your Business: Trends Driving the Next Decade
  • Revolutionizing Tomorrow: The AI-Powered Future of Internet Technology
  • 5 Unconventional Internet Marketing Strategies That Actually Convert

Fiverr

Fiverr Logo   

BL

SeedBL

Seedbacklink

Tags

2021 Acura Rdx Technology Package 2021 Acura Tlx Technology Package 2022 Acura Mdx Technology Package Align Technology Stock Applied Racing Technology Artificial Intelligence Technology Solutions Inc Assisted Reproductive Technology Battery Technology Stocks Benjamin Franklin Institute Of Technology Chief Technology Officer Color Star Technology Craft Design Technology Definition Of Technology Definitive Technology Speakers Element Materials Technology Health Information Technology Salary Ice Mortgage Technology Information Technology Definition Information Technology Degree Information Technology Salary Interactive Response Technology International Game Technology Lacrosse Technology Atomic Clock La Crosse Technology Weather Station Luokung Technology Stock Marvell Technology Stock Price Maytag Commercial Technology Washer Microchip Technology Stock Micron Technology Stock Price Mrna Technology History Mrna Vaccine Technology Nyc College Of Technology Penn College Of Technology Recombinant Dna Technology Rlx Technology Stock Robert Half Technology Science And Technology Sharif University Of Technology Smart Home Technology Stevens Institute Of Technology Ranking Symphony Technology Group Technology In The Classroom Technology Readiness Level Technology Stores Near Me Thaddeus Stevens College Of Technology

PHP 2026

franciegrubba
cutnewyork

You may have missed

The Future of Computing: Unlocking the Power of Quantum AI
  • Computer & Technology

The Future of Computing: Unlocking the Power of Quantum AI

Lisa H. Shelton September 3, 2026
The Future Unplugged: How AI is Redefining Human Creativity
  • Technology

The Future Unplugged: How AI is Redefining Human Creativity

Lisa H. Shelton September 3, 2026
Future-Proofing Your Business: Trends Driving the Next Decade
  • Business

Future-Proofing Your Business: Trends Driving the Next Decade

Lisa H. Shelton September 3, 2026
Revolutionizing Tomorrow: The AI-Powered Future of Internet Technology
  • internet

Revolutionizing Tomorrow: The AI-Powered Future of Internet Technology

Lisa H. Shelton September 3, 2026
charmnailspa.com | MoreNews by AF themes.

WhatsApp us