cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Caute_cautim
Community Champion

Spring4Shell Bug - yes another Log4J issue

Hi All

 

It looks like another Spring for Java development has sprung up, even though it is Autumn in the Southern Hemisphere.  It looks very much another extension to Log4J and Spring for Cloud with serious consequences.

 

https://threatpost.com/critical-rce-bug-spring-log4shell/179173/

 

Regards

 

Caute_Cautim

3 Replies
csjohnng
Community Champion

Yes, will be another busy week.... there are 2 related CVEs and the RCE is really bad, even worst than the log4shell

 

https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/

 

virtual patching and patching...

 

John
AppDefects
Community Champion

Here is an analysis (one of many out there) that describes the similarities with Log4j. This one describes the exploit scenario associated with Spring Core and the dependencies 

Caute_cautim
Community Champion

HI All

 

This is a follow up to to my original piece - it appears the number of systems affected is far greater than organisations anticipated.   Some sleepless nights for many.

 

https://www.darkreading.com/application-security/vulnerable-spring-framework-instances-estimated-at-...

 

Regards

 

Caute_Cautim