KEVIntel
9.8
CVSS
Critical

CVE-2022-22965

PUBLISHED

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific...

Exploited in the wild Remote Low complexity No user interaction
Vendor
VMware
Product
Spring Framework
Published
Apr 01, 2022
EPSS
94.4% · 100% pctl

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

java cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-04-04 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Apr 04, 2022
The Shadowserver (via CIRCL) May 31, 2026

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

spring_framework_rce_spring4shell

metasploit · Created Unknown

Metasploit module for CVE-2022-22965

jakabakos/CVE-2022-22965-Spring4Shell

github · Created 2023-06-20 11:45:29 UTC · 2 stars

PoC and exploit for CVE-2022-22965 Spring4Shell

BKLockly/CVE-2022-22965

github · Created 2023-06-03 16:39:50 UTC · 3 stars

Poc&Exp,支持批量扫描,反弹shell

zangcc/CVE-2022-22965-rexbb

github · Created 2022-12-28 04:50:16 UTC · 100 stars

CVE-2022-22965\Spring-Core-RCE核弹级别漏洞的rce图形化GUI一键利用工具,基于JavaFx开发,图形化操作更简单,提高效率。

iloveflag/Fast-CVE-2022-22965

github · Created 2022-11-08 13:45:35 UTC · 4 stars

CVE-2022-22965图形化检测工具

D1mang/Spring4Shell-CVE-2022-22965

github · Created 2022-07-05 03:03:31 UTC · 2 stars

EXP for Spring4Shell(CVE-2022-22965)

khidottrivi/CVE-2022-22965

github · Created 2022-04-27 07:57:50 UTC · 3 stars

mariomamo/CVE-2022-22965

github · Created 2022-04-23 09:01:22 UTC · 5 stars

p1ckzi/CVE-2022-22965

github · Created 2022-04-12 14:59:42 UTC · 21 stars

spring4shell | CVE-2022-22965

CalumHutton/CVE-2022-22965-PoC_Payara

github · Created 2022-04-07 15:26:15 UTC · 3 stars

wikiZ/springboot_CVE-2022-22965

github · Created 2022-04-07 02:30:26 UTC · 6 stars

CVE-2022-22965 pocsuite3 POC

alt3kx/CVE-2022-22965

github · Created 2022-04-07 00:08:16 UTC · 102 stars

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

LudovicPatho/CVE-2022-22965_Spring4Shell

github · Created 2022-04-05 20:34:36 UTC · 2 stars

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

0xrobiul/CVE-2022-22965

github · Created 2022-04-05 15:45:47 UTC · 3 stars

Exploit Of Spring4Shell!

netcode/Spring4shell-CVE-2022-22965-POC

github · Created 2022-04-04 20:16:06 UTC · 3 stars

Another spring4shell (Spring core RCE) POC

sunnyvale-it/CVE-2022-22965-PoC

github · Created 2022-04-04 13:44:39 UTC · 7 stars

CVE-2022-22965 (Spring4Shell) Proof of Concept

itsecurityco/CVE-2022-22965

github · Created 2022-04-03 06:43:07 UTC · 15 stars

Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5

wjl110/CVE-2022-22965_Spring_Core_RCE

github · Created 2022-04-02 09:13:54 UTC · 13 stars

CVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用

Wrin9/CVE-2022-22965

github · Created 2022-04-02 03:17:48 UTC · 7 stars

CVE-2022-22965 POC

me2nuk/CVE-2022-22965

github · Created 2022-04-01 13:35:01 UTC · 13 stars

Spring Framework RCE via Data Binding on JDK 9+ / spring4shell / CVE-2022-22965

zer0yu/CVE-2022-22965

github · Created 2022-04-01 12:37:32 UTC · 11 stars

Spring4Shell (CVE-2022-22965)

tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce

github · Created 2022-04-01 07:55:26 UTC · 37 stars

批量无损检测CVE-2022-22965

nu0l/CVE-2022-22965

github · Created 2022-04-01 06:50:21 UTC · 4 stars

Spring-0day/CVE-2022-22965

Axx8/SpringFramework_CVE-2022-22965_RCE

github · Created 2022-04-01 04:51:44 UTC · 75 stars

SpringFramework 远程代码执行漏洞CVE-2022-22965

likewhite/CVE-2022-22965

github · Created 2022-04-01 02:25:46 UTC · 3 stars

CVE-2022-22965 EXP

viniciuspereiras/CVE-2022-22965-poc

github · Created 2022-03-31 19:19:52 UTC · 13 stars

CVE-2022-22965 poc including reverse-shell support

rwincey/spring4shell-CVE-2022-22965

github · Created 2022-03-31 18:09:58 UTC · 2 stars

colincowie/Safer_PoC_CVE-2022-22965

github · Created 2022-03-31 16:58:56 UTC · 44 stars

A Safer PoC for CVE-2022-22965 (Spring4Shell)

GuayoyoCyber/CVE-2022-22965

github · Created 2022-03-31 16:14:36 UTC · 6 stars

Vulnerabilidad RCE en Spring Framework vía Data Binding on JDK 9+ (CVE-2022-22965 aka "Spring4Shell")

alt3kx/CVE-2022-22965_PoC

github · Created 2022-03-31 15:43:06 UTC · 17 stars

Spring Framework RCE (Quick pentest notes)

Kirill89/CVE-2022-22965-PoC

github · Created 2022-03-31 13:21:49 UTC · 28 stars

Bouquets-ai/CVE-2022-22965-GUItools

github · Created 2022-03-31 02:00:18 UTC · 16 stars

spring-core单个图形化利用工具,CVE-2022-22965及修复方案已出

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit

  • Added to KEVIntel