This article covers Spring4Shell, an RCE (Remote Code Execution) vulnerability discovered in Java Spring technologies.
Spring4Shell: A term used to describe a series of vulnerabilities affecting Java Spring-related technologies
On March 29, 2022, VMWare announced a vulnerability referenced as CVE-2022-22963 in the Spring Cloud Function product (a technology used to implement serverless services).
On the same day, a second Remote Code Execution vulnerability was announced in the Spring Framework product (a framework that simplifies Java project development).
On 03/31/2022, following extensive discussion on forums, this second vulnerability was assigned the code CVE-2022-22965.
Both vulnerabilities are referred to on social media as Spring4Shell due to their connection to Spring technologies, and because these technologies are often Java libraries deployed similarly to Log4J (the Java library targeted by Log4Shell in December 2021).
At the time of writing, the NVD has not yet created an official entry for these vulnerabilities.
The French National Cybersecurity Agency (ANSSI) has published the following advisory: CERTFR-2022-AVI-297.
Spring4Shell refers to vulnerability CVE-2022-22965
The community has used the name Spring4Shell to describe the entire situation, sometimes causing a bit of confusion, in reference to the Log4Shell vulnerability.
However, the consensus is that Spring4Shell is more specifically linked to CVE-2022-22965, which has a much lower impact than the Log4Shell vulnerability.
Indeed, Log4J was a technology embedded in a vast number of components, and its default configuration very often allowed for the exploitation of vulnerability CVE-2021-44228.
In this case, the Spring Framework has a default configuration that significantly limits the exploitability of CVE-2022-22965.
Cyberwatch therefore recommends updating vulnerable technologies as soon as possible, but advises against activating crisis response teams without clear evidence of an attack.
Which configurations are vulnerable?
CVE-2022-22963 affects Spring Cloud Function components up to versions 3.1.6 and 3.2.2
Vulnerability CVE-2022-22963 affects the Spring Cloud Function library in the following versions:
- Any version up to and including 3.1.6;
- Any 3.2.X version up to and including 3.2.2.
CVE-2022-22965 affects Spring Framework and Spring Boot components up to versions 5.2.19 and 5.3.17
Vulnerability CVE-2022-22965 affects Spring Framework libraries in the following versions on Java 9 or higher:
- Any version 5.0.X, 5.1.X, 5.2.X, up to and including 5.2.19;
- Any version 5.3.X up to and including 5.3.17.
It also affects components that include it, such as the Spring Boot library in the following versions on Java 9 or higher:
- Any version 2.0.X, 2.1.X, 2.2.X, 2.3.X, 2.4.X, up to 2.5.11;
- Any version 2.6.X up to and including 2.6.5.
According to the publisher, vulnerable deployments are exclusively those that meet the following specific criteria:
- deployment of the Java application as a WAR file;
- execution of the Java application with Apache Tomcat;
- presence of one of the spring-webmvc or spring-webflux dependencies.
This is why this CVE is more difficult to exploit than Log4Shell, and therefore much less severe.
How can I detect the presence of Spring4Shell in my information system?
Two approaches can be used to search for Spring4Shell in your information system: by scanning the hard drive, or by attempting injections on web applications.
Hard drive scanning approach
A hard drive scanning approach allows you to identify JAR / WAR / EAR libraries and check them for the presence of Spring Boot or Spring Framework libraries.
Two basic examples are available for Linux and Windows, made available to the community under the GPLv3 license.
Example search script for Linux
#!/bin/bash
###################################################################################
# ======================== Spring4Shell scanning scripts ==========================
#
# VERSION 1.0.0
#
# AUTHOR Cyberwatch SAS
#
# PROJECTURI https://cyberwatch.fr
#
# DESCRIPTION
# Scans the filesystem for WAR files containing the Spring core library.
# Provides a list of identified files in CPE format for Cyberwatch.
#
# SYNOPSIS
# Locate Spring files and output the results in CPE format for Cyberwatch scans.
###################################################################################
toplevel='/'
sudo=''
sudo -n find -version > /dev/null && sudo='sudo -n'
python='python'
if command -v python3 > /dev/null ; then
python='python3'
elif command -v python2 > /dev/null ; then
python='python2'
fi
pyscript=$(mktemp --tmpdir cyberwatch-XXXXXX.py)
cat > "$pyscript" <<PYTHON
import io
import os.path
import re
import sys
import zipfile
spring_re = re.compile('^spring-core.*-(?P<version>[0-9][0-9.]*[0-9]).*jar$')
def process_archive(archive_file, archive_path):
try:
with zipfile.ZipFile(archive_file) as archive:
for member_path in archive.namelist():
full_path = os.path.join(archive_path, member_path)
m = spring_re.match(os.path.basename(archive_path))
if m:
print('# WAR file found with vulnerable Spring Framework lib')
print('# ' + full_path)
print('CPE:cpe:2.3:a:vmware:spring_framework:' + m.group('version') + ':*:*:*:*:*:*:*')
return
if os.path.splitext(member_path)[1].lower() in ['.jar', '.war', '.ear', '.zip']:
process_archive(io.BytesIO(archive.read(member_path)), full_path)
except Exception as e:
print("# Error reading " + archive_path + ": " + str(e))
for line in sys.stdin:
path = line.rstrip()
process_archive(path, path)
PYTHON
$sudo find "$toplevel" -xdev -type f \( -iname '*.war' \) |
$sudo $python -- "$pyscript"
rm -- "$pyscript"
Example search script for Windows
<#PSScriptInfo
.VERSION 1.0.0
.GUID cee16958-1b73-41c0-a6f2-a94e4ef5295b
.AUTHOR Cyberwatch SAS
.PROJECTURI https://cyberwatch.fr
.Description
Scans the filesystem for WAR files containing the Spring Core library.
Provides a list of the identified files in CPE format for Cyberwatch.
WARNING: This script requires PowerShell v3 or higher!
.SYNOPSIS
Finds Spring Framework files and outputs the results in CPE format for Cyberwatch analysis.
#>
Add-Type -Assembly 'System.IO.Compression'
function Invoke-Archive {
param (
[System.IO.Stream] $archiveStream,
[string] $archivePath
)
try {
$archive = New-Object System.IO.Compression.ZipArchive $archiveStream
} catch {
"# Warning: Unable to open archive $($archivePath): $($_.FullyQualifiedErrorID)"
return
}
foreach ($entry in $archive.Entries) {
$fullPath = "$archivePath/$($entry.FullName)"
if ([System.IO.Path]::GetFileName($archivePath) -match '^spring-core.*-(\d[\d.]*\d).*jar$') {
'# WAR file found with vulnerable Spring Framework lib'
"# $fullPath"
"CPE:cpe:2.3:a:vmware:spring_framework:$($Matches.1):*:*:*:*:*:*:*"
return
}
if ([System.IO.Path]::GetExtension($entry.Name) -in ".jar", ".war", ".ear", ".zip") {
$subarchive = $entry.Open()
Invoke-Archive $subarchive $fullPath
}
}
}
foreach ($drive in Get-PSDrive -PSProvider FileSystem) {
"# Browsing $($drive.Root)"
foreach ($path in Get-ChildItem -Path $drive.Root -File -Recurse -Include "*.war" -ErrorAction SilentlyContinue -ErrorVariable UnscannablePaths) {
$file = [System.IO.File]::OpenRead($path)
Invoke-Archive $file $path
}
foreach ($Exception in $UnscannablePaths) {
"# Warning: Unable to scan $($Exception.TargetObject): $($Exception.FullyQualifiedErrorID)"
}
""
}
# END
You will then get one line per WAR file containing a vulnerable library, along with the installed versions. Comparing these with the versions listed in this article will allow you to verify whether your system is vulnerable.
Injection-based approach
The injection involves creating specific web requests that use specially crafted headers and POST data to trigger the vulnerability.
An example attack script is available on a GitHub project by Lunasec.
Running this script against the target will allow you to verify whether it is vulnerable.
Cyberwatch also provides the community with a free website scanning module via its open-source scanner, Wapiti, and PR 275.
How to fix CVE-2022-22963 and CVE-2022-22965 Spring4Shell?
The safest approach is to update the vulnerable libraries according to the list below.
Recommendations for fixing CVE-2022-22963
- Install Spring Cloud Function version 3.1.7 for 3.1.X branches or lower;
- Install Spring Cloud Function version 3.2.3 for the 3.2.X branch.
Recommendations for fixing CVE-2022-22965 Spring4Shell
For Spring Boot:
- Install Spring Boot version 2.5.12 for 2.5.X branches or lower;
- Install Spring Boot version 2.6.6 for the 2.6.X branch.
For Spring Core:
- Install Spring Framework 5.2.20 for 5.2.X branches or lower;
- Install Spring Framework 5.3.18 for the 5.3.X branch.
Additionally, Apache Tomcat has released updates to mitigate this CVE:
- Install Apache Tomcat 8.5.78 for 8.X branches or lower;
- Install Apache Tomcat 9.0.62 for 9.0.X branches;
- Install Apache Tomcat 10.0.20 for 10.0.X branches.
Also discover Cyberwatch Vulnerability Manager, our vulnerability management solution
Cyberwatch Vulnerability Manager is a vulnerability management solution featuring detection, prioritization, and remediation.
Cyberwatch Vulnerability Manager is specifically capable of detecting Spring4Shell on your information system via local or web scans, helping you make the right decisions.
Feel free to request a demo via the dedicated form.
Update history for this article
03/31/2022 6:40 PM: initial article draft following the publication of CVE-2022-22965.
03/31/2022 9:22 PM: updated free scripts to target only WAR-based configurations.
04/01/2022 4:55 PM: added recommendations regarding Apache Tomcat patches.
