CVE-2021-44228-Scanner icon indicating copy to clipboard operation
CVE-2021-44228-Scanner copied to clipboard

Spring Framework for Java vulnerable to remote code execution CVE-2022-22965

Open doctore74 opened this issue 2 years ago • 9 comments

Hi,

do you have any plans to integrate the detection for Spring4Shell (CVE-2022-22965)?

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22965

https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/

doctore74 avatar Apr 01 '22 12:04 doctore74

No.. I think it's relatively easy to spot vulnerable spring apps since operator can see any tomcat instances. I reviewed some real exploit payload in the wild and concluded it's easy to detect and block using WAF. If there are many demands for spring scanner, I will reconsider about spring scanner.. (but spring scanner should be another repo in that case)

xeraph avatar Apr 01 '22 12:04 xeraph

I see. Thanks for the quick answer.

doctore74 avatar Apr 01 '22 15:04 doctore74

Hi @xeraph ! I would Love to see a spring scanner i think it could be very helpful!

cstegm avatar Apr 01 '22 15:04 cstegm

hi, +1 :) since you are already extracting all jar and war files it would be really cool to have searched for both issues, for now I use https://github.com/hillu/local-spring-vuln-scanner and run both commands periodically

funksen avatar Apr 02 '22 09:04 funksen

I would love to see a CVE-2022-22965 scanner !

romestylez avatar Apr 04 '22 08:04 romestylez

@xeraph An integration would be best practise. We would not need a second run over the same files.

doctore74 avatar Apr 04 '22 08:04 doctore74

@xeraph An integration would be best practise. We would not need a second run over the same files.

I would like another tool. Possibly its different servers then before. So two tools would be great.

romestylez avatar Apr 04 '22 08:04 romestylez

Hi, I also would love to see Spring scanning, it will be great :)

DoronGaznavi avatar Apr 05 '22 06:04 DoronGaznavi

I will add my name to the list for a scanner. Thanks.

greg-michael avatar Apr 11 '22 19:04 greg-michael