CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 10, 2022
- Published Date
- April 01, 2022
- Last Updated
- January 29, 2025
- Vendor
- n/a
- Product
- Spring Framework
- Description
- A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-04-04 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/spring_framework_rce_spring4shell.rb | 2025-04-29 11:01:23 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22965.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
spring_framework_rce_spring4shell
Type: metasploit • Created: Unknown
jakabakos/CVE-2022-22965-Spring4Shell
Type: github • Created: 2023-06-20 11:45:29 UTC • Stars: 2
BKLockly/CVE-2022-22965
Type: github • Created: 2023-06-03 16:39:50 UTC • Stars: 3
zangcc/CVE-2022-22965-rexbb
Type: github • Created: 2022-12-28 04:50:16 UTC • Stars: 100
devengpk/CVE-2022-22965
Type: github • Created: 2022-12-12 16:30:05 UTC • Stars: 0
iloveflag/Fast-CVE-2022-22965
Type: github • Created: 2022-11-08 13:45:35 UTC • Stars: 4
D1mang/Spring4Shell-CVE-2022-22965
Type: github • Created: 2022-07-05 03:03:31 UTC • Stars: 2
khidottrivi/CVE-2022-22965
Type: github • Created: 2022-04-27 07:57:50 UTC • Stars: 3
mariomamo/CVE-2022-22965
Type: github • Created: 2022-04-23 09:01:22 UTC • Stars: 5
p1ckzi/CVE-2022-22965
Type: github • Created: 2022-04-12 14:59:42 UTC • Stars: 21
CalumHutton/CVE-2022-22965-PoC_Payara
Type: github • Created: 2022-04-07 15:26:15 UTC • Stars: 3
wikiZ/springboot_CVE-2022-22965
Type: github • Created: 2022-04-07 02:30:26 UTC • Stars: 6
alt3kx/CVE-2022-22965
Type: github • Created: 2022-04-07 00:08:16 UTC • Stars: 102
LudovicPatho/CVE-2022-22965_Spring4Shell
Type: github • Created: 2022-04-05 20:34:36 UTC • Stars: 2
0xrobiul/CVE-2022-22965
Type: github • Created: 2022-04-05 15:45:47 UTC • Stars: 3
netcode/Spring4shell-CVE-2022-22965-POC
Type: github • Created: 2022-04-04 20:16:06 UTC • Stars: 3
sunnyvale-it/CVE-2022-22965-PoC
Type: github • Created: 2022-04-04 13:44:39 UTC • Stars: 7
itsecurityco/CVE-2022-22965
Type: github • Created: 2022-04-03 06:43:07 UTC • Stars: 15
wjl110/CVE-2022-22965_Spring_Core_RCE
Type: github • Created: 2022-04-02 09:13:54 UTC • Stars: 13
Wrin9/CVE-2022-22965
Type: github • Created: 2022-04-02 03:17:48 UTC • Stars: 7
me2nuk/CVE-2022-22965
Type: github • Created: 2022-04-01 13:35:01 UTC • Stars: 13
zer0yu/CVE-2022-22965
Type: github • Created: 2022-04-01 12:37:32 UTC • Stars: 11
tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce
Type: github • Created: 2022-04-01 07:55:26 UTC • Stars: 37
nu0l/CVE-2022-22965
Type: github • Created: 2022-04-01 06:50:21 UTC • Stars: 4
Axx8/SpringFramework_CVE-2022-22965_RCE
Type: github • Created: 2022-04-01 04:51:44 UTC • Stars: 75
likewhite/CVE-2022-22965
Type: github • Created: 2022-04-01 02:25:46 UTC • Stars: 3
viniciuspereiras/CVE-2022-22965-poc
Type: github • Created: 2022-03-31 19:19:52 UTC • Stars: 13
rwincey/spring4shell-CVE-2022-22965
Type: github • Created: 2022-03-31 18:09:58 UTC • Stars: 2
colincowie/Safer_PoC_CVE-2022-22965
Type: github • Created: 2022-03-31 16:58:56 UTC • Stars: 44
GuayoyoCyber/CVE-2022-22965
Type: github • Created: 2022-03-31 16:14:36 UTC • Stars: 6
alt3kx/CVE-2022-22965_PoC
Type: github • Created: 2022-03-31 15:43:06 UTC • Stars: 17
Kirill89/CVE-2022-22965-PoC
Type: github • Created: 2022-03-31 13:21:49 UTC • Stars: 28
Bouquets-ai/CVE-2022-22965-GUItools
Type: github • Created: 2022-03-31 02:00:18 UTC • Stars: 16