Spring4Shell is a a zero-dat vulnerability in the Spring Core Java network. It's tracked as CVE-2022-22965. Impacted users must upgrade to the latest versions of Spring immediately.
Spring4Shell
Key takeaways
- When exploited, Spring4Shell could facilitate Remote Code Injection (RCE)
- The current known exploit only occurs on Tomcat servers, but its limitation to this environment isn't yet conclusive.
- Impacted users must upgrade to the latest versions of Spring immediately.
Reviewed by
No items found.
See UpGuard In Action
Book a free, personalized onboarding call with one of our cybersecurity experts.
More from our blog
Learn more about the latest issues in cybersecurity.
The Vendor Assurance Confidence Gap: Why It’s Widest With Your Most Critical Vendors
The Vendor Assurance Confidence Gap: Why It’s Widest With Your Most Critical Vendors
Vendor assurance efforts are rising while confidence in them is falling. This gap is widest with the vendors that matter most. Here’s why.
Sign up for our newsletter
UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.