2022å¹´3æ31æ¥ãSpring Frameworkã«è´å½çãªèå¼±æ§ã確èªãããä¿®æ£çãå ¬éããã¾ãããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã ï¼ï¼ä½ãèµ·ããã®ï¼ JDK9以ä¸ã§å®è¡ãããSpringMVCãSpringWebFluxã§ãªã¢ã¼ãã³ã¼ãå®è¡ãå¯è½ãªèå¼±æ§ï¼CVE-2022-22965ï¼ã確èªããããèå¼±æ§ã®é称ã«Spring4shellã¾ãã¯SpringShellãç¨ãããã¦ããã Spring Frameworkã¯Javaã§æ¡ç¨ããã主æµãªãã¬ã¼ã ã¯ã¼ã¯ã®1ã¤ã®ãããJavaã§å®è¡ãããWebã¢ããªã±ã¼ã·ã§ã³ã§å©ç¨ãã¦ããå¯è½æ§ãããã 2022å¹´3æ31æ¥æç¹ã§èå¼±æ§ã®Exploitã³ã¼ããåºåã£ã¦ãããé¢é£ããã¤ã³ã¿ã¼ãããä¸ã®æ´»åãæ¢ã«å ±åããã¦ããã ï¼ï¼èå¼±æ§ãæªç¨ãããã¨ä½ãèµ·ããã®ï¼ èå¼±æ§ãæªç¨ãããå ´åããªã¢ã¼ãããä»»æã³ã¼ãå®è¡ãè¡ããããã¨ã§ãæ©å¯æ å ±ã®
{{#tags}}- {{label}}
{{/tags}}