HomeSecurityZero-day in Java Spring allows remote code execution

Zero-day in Java Spring allows remote code execution

A new zero-day vulnerability recently discovered in the Java Spring Core, known as "Spring4Shell," allows unauthenticated remote code execution in applications.

See also: Google fixes Chrome zero-day bug used in attacks

Zero day

Spring is a very popular application framework that allows software developers to quickly and easily develop Java applications with enterprise-grade functionality. These applications can then be deployed on servers, such as Apache Tomcat, as standalone packages with all the required dependencies.

Information about a critical Spring Core remote code execution vulnerability was released on the QQ chat service and a Chinese cybersecurity website.

An exploit for this zero-day vulnerability was leaked briefly and then removed, but not before cybersecurity researchers were able to download the code.

Since then, many researchers and security companies have confirmed that the vulnerability is valid and of significant concern.

While it was initially thought to affect all Spring applications running on Java 9 or later, it was later found that there are specific requirements that must be met for a Spring application to be vulnerable.

See also: Windows zero-day vulnerability remains unpatched

Will Dormann, a vulnerability analyst at CERT/CC, said that an application must also use “Spring Beans,” “Spring Parameter Binding,” and a “Spring Parameter Binding must be configured to use a non-basic parameter type, such as POJOs.”

Java Spring

Cybersecurity firm Praetorian also confirmed that the bug relies on specific configurations to exploit.

While the requirements may limit the size of the target, the Spring4Shell vulnerability is already being actively used in attacks.

Threat actors can use these exploits to execute commands on the server, which would allow full remote access to the device.

This zero-day vulnerability has not been patched. Therefore, one line of defense would be to modify the source code of custom Spring applications to ensure that these “guardrails” are in place. However, organizations using third-party applications that are susceptible to this vulnerability cannot benefit from this approach.

See also: New JavaScript malware infects Windows PCs with RATs

If your organization has a web application firewall (WAF) in place, profiling any affected Spring-based applications to see what strings can be used in WAF detection rule sets would help prevent malicious exploitation attempts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS