To access material, start machines and answer questions login.
Set up your virtual environment
In late March 2022, two remote command execution vulnerabilities in the Java Spring framework (opens in new tab) were made public. The first of these vulnerabilities affects a component of the framework called "Spring Cloud Functions". The second, arguably more serious vulnerability, affects a component in "Spring Core" — the heart of the framework — thus significantly increasing the vulnerability's potential impact and earning it the name "Spring4Shell" (a play on Log4Shell, the name of a brutal vulnerability disclosed at the end of 2021).
For various reasons, there has been a lot of confusion surrounding these vulnerabilities in the wider infosec community. As such, this room may be updated as new information comes to light. On a similar note, the impact of Spring4Shell is currently unknown; only time will tell how wide-spread the vulnerability is in the wild.
This room will provide an overview of the Spring4Shell vulnerability in Spring Core, as well as give you an opportunity to exploit it for yourself in the vulnerable machine attached to this task. We will start by taking a look at the vulnerability at a high-level, before exploiting the lab machine for ourselves.
Let's begin!
Deploy the lab machine by clicking the green button at the top of this task!
Note: This machine will take 2-3 minutes to start up completely.
Ready to learn Cyber Security?
The Spring4Shell: CVE-2022-22965 room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

