Skip to main content
Room Banner
Back to all walkthroughs
Room Icon

Spring4Shell: CVE-2022-22965

Max room.

Interactive lab for exploiting Spring4Shell (CVE-2022-22965) in the Java Spring Framework

info

20 min

15,787

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

In late March 2022, two remote command execution vulnerabilities in the Java Spring framework (opens in new tab) were made public. The first of these vulnerabilities affects a component of the framework called "Spring Cloud Functions". The second, arguably more serious vulnerability, affects a component in  "Spring Core" —  the heart of the framework — thus significantly increasing the vulnerability's potential impact and earning it the name "Spring4Shell" (a play on Log4Shell, the name of a brutal vulnerability disclosed at the end of 2021).

For various reasons, there has been a lot of confusion surrounding these vulnerabilities in the wider infosec community. As such, this room may be updated as new information comes to light. On a similar note, the impact of Spring4Shell is currently unknown; only time will tell how wide-spread the vulnerability is in the wild.

This room will provide an overview of the Spring4Shell vulnerability in Spring Core, as well as give you an opportunity to exploit it for yourself in the vulnerable machine attached to this task. We will start by taking a look at the vulnerability at a high-level, before exploiting the lab machine for ourselves.

Let's begin!

Answer the questions below

Deploy the lab machine by clicking the green button at the top of this task!

Note: This machine will take 2-3 minutes to start up completely.