CVE-2022-22965: Spring4Shell
A remote code execution vulnerability in Spring Framework's data binding, exploitable on applications deployed as a WAR to Apache Tomcat and running on JDK 9 or later. A crafted HTTP request walks the class loader through Java's ClassLoader property chain to overwrite server configuration and drop a webshell.
View the authoritative record on NVD ↗Affected software
- Spring Framework 5.3.0 through 5.3.17
- Spring Framework 5.2.0 through 5.2.19
How it's exploited
Submit a crafted HTTP request whose parameters walk the class.module.classLoader property chain, reachable through Spring's data binding, to overwrite Tomcat's logging configuration and drop a JSP webshell that executes attacker-supplied code.
Severity
CVE-2022-22965 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2022-22965 is categorized under CWE-94, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this (white-box)
This weakness (Code Injection) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 6 rules for it, flagging the issue directly in your source code as part of the pentest.
Remediation
Upgrade to Spring Framework 5.3.18 / 5.2.20 or later (Spring Boot 2.6.6 / 2.5.12), or apply the documented WebDataBinder disallowedFields workaround if an immediate upgrade is not possible.
Frequently asked questions
What is CVE-2022-22965?
A remote code execution vulnerability in Spring Framework's data binding, exploitable on applications deployed as a WAR to Apache Tomcat and running on JDK 9 or later. A crafted HTTP request walks the class loader through Java's ClassLoader property chain to overwrite server configuration and drop a webshell.
How severe is CVE-2022-22965?
CVE-2022-22965 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2022-22965?
CVE-2022-22965 affects Spring Framework 5.3.0 through 5.3.17; Spring Framework 5.2.0 through 5.2.19.
How do you fix CVE-2022-22965?
Upgrade to Spring Framework 5.3.18 / 5.2.20 or later (Spring Boot 2.6.6 / 2.5.12), or apply the documented WebDataBinder disallowedFields workaround if an immediate upgrade is not possible.
Where is the authoritative record for CVE-2022-22965?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2022-22965 at https://nvd.nist.gov/vuln/detail/CVE-2022-22965, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest