ç®æ¬¡ å½±é¿ãåããã½ããã¦ã§ã¢ã¨ãã¼ã¸ã§ã³ Spring Frameworkã®èæ¯ CVE-2022-22965ã®æ ¹æ¬åå åæ ã¯ã©ã¹ãã¼ãã¼æªç¨ã®èæ¯ ä¾µå®³ããããµã¼ãã¼ä¸ã§ã®ãªã¢ã¼ããµã¼ãã¼ã¸ã®ãªãã¼ã¹ã·ã§ã«æ¥ç¶ç¢ºç« SpringShellã®ã¨ã¯ã¹ããã¤ã å®éã«è¦³æ¸¬ãããäºä¾ çµè« 追å ãªã½ã¼ã¹ IoC å½±é¿ãåããã½ããã¦ã§ã¢ã¨ãã¼ã¸ã§ã³ æ¢åã®ã¨ã¯ã¹ããã¤ãã®æ¦å¿µå®è¨¼(PoC)ã¯ã以ä¸ã®æ¡ä»¶ã§åä½ãã¾ãã JDK 9ä»¥ä¸ Servletã³ã³ããã¨ãã¦ã®Apache Tomcat (Spring Bootã®å®è¡å¯è½jarã¨ã¯ç°ãªã)å¾æ¥ã®WARã¨ãã¦ã®ããã±ã¼ã¸å spring-webmvc ã¾ã㯠spring-webflux ã¨ã®ä¾åé¢ä¿ Spring Framework ãã¼ã¸ã§ã³ 5.3.0 ãã 5.3.17, 5.2.0 ãã 5.2.19, ããã³ãã以åã®ãã¼ã¸ã§ã³
![[2022-04-19 JST Windows/Linuxã«ããä¿è·ã»ã¯ã·ã§ã³ãæ´æ°] CVE-2022-22965: Spring Coreã«ãªã¢ã¼ãã³ã¼ãå®è¡èå¼±æ§(SpringShell)ããã§ã«å®éã®ã¨ã¯ã¹ããã¤ãã](https://cdn-ak-scissors.b.st-hatena.com/image/square/bcebaec7d06409cf03bdb2d18c851c945592a82c/height=288;version=1;width=512/https%3A%2F%2Funit42.paloaltonetworks.com%2Fwp-content%2Fuploads%2F2024%2F06%2F01_Vulnerabilities_1920x900.jpg)
{{#tags}}- {{label}}
{{/tags}}