Warning of dangerous Spring4Shell vulnerability, there are signs of scanning and exploiting
Spring has just released an urgent update to patch the Spring4Shell remote code execution zero-day vulnerability. Information about this vulnerability was leaked on the internet before the patch was released.
Soon after, a guide to exploiting the Spring4Shell vulnerability in the Spring Framework was posted on GitHub and deleted. But the internet was an open world, so that exploit was quickly re-shared elsewhere and tested and confirmed by security researchers as a standard Spring4Shell-only exploit.
The Spring4Shell vulnerability exists in Spring Core, a core component of the Spring Framework open source code. Currently, Spring Framework is commonly used in web applications. It is estimated that about 50% of web applications written in Java use Spring Core. According to the assessment, Sping4Shell is more dangerous than the Log4Shell vulnerability, one of the most dangerous vulnerabilities of the decade that was discovered at the end of 2021.
According to the Cybersecurity Monitoring Center, there have been groups of hackers that have scanned and tested Spring4Shell on some technology systems of agencies and organizations.
To fix the vulnerability, IT admins need to update to the following versions:
- Spring Framework 5.3.18 and Spring Framework 5.2.20.
- Spring Boot 2.5.12.
- Spring Boot 2.6.6 (to be released soon).
The Spring4Shell vulnerability is particularly dangerous because developers often use sample code for their applications. Therefore, many applications are at risk of being attacked online.
Admins need to prioritize deploying updates as soon as possible. The reason is because hackers are actively exploiting new vulnerabilities.
- If your body has these 12 signs, you are eating too much sugar!
- Your 10 kidney warning signs are having problems
- Eye changes may signal cancer, diabetes and high blood pressure
- Warning: Detecting a very serious vulnerability in Cyberoam, a common firewall system in Vietnam
- 7 warning signs your body is 'calling for help'
- How to install and use a vulnerability scanner in Linux
- Signs You May Have 'Brain Rot'
- 10 signs appear on the body of health warning you should not be ignored
- 10 investment scam warning signs you need to know
- A month before your heart attack, your body will show 8 warning signs!
- Metasploit - Tool to exploit vulnerabilities
- 8 abnormal signs on the skin warning the body is having serious health problems
- New zero-day vulnerability warning in Windows Search, Windows protocol nightmare getting worse
- 9 abnormal signs in the legs warning the body is having health problems