40045Spring4Shell

PUBLISHEDsecurity alertHigh
Active

Metadata

Alert ID:
40045
Risk:
High
Type:
Active

摘要

The application appears to be vulnerable to CVE-2022-22965 (otherwise known as Spring4Shell) - remote code execution (RCE) via data binding.

解决方案

Upgrade Spring Framework to versions 5.3.18, 5.2.20, or newer.

参考