Spring4Shell is a a zero-dat vulnerability in the Spring Core Java network. It's tracked as CVE-2022-22965. Impacted users must upgrade to the latest versions of Spring immediately.
Spring4Shell
Key takeaways
- When exploited, Spring4Shell could facilitate Remote Code Injection (RCE)
- The current known exploit only occurs on Tomcat servers, but its limitation to this environment isn't yet conclusive.
- Impacted users must upgrade to the latest versions of Spring immediately.
Reviewed by
No items found.
See UpGuard In Action
Book a free, personalized onboarding call with one of our cybersecurity experts.
More from our blog
Learn more about the latest issues in cybersecurity.
Sign up for our newsletter
Stay up-to-date on everything UpGuard with our monthly newsletter, full of product updates, company highlights, free cybersecurity resources, and more.