Skip to content

anair-it/springshell-vuln-POC

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

13 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Replicate spring shell 0-day vulnerability

SCA scanners may report a critical security violation due to the spring-beans version used. But that doesn't mean the application is vulnerable. These POC projects should help you understand the issue and verify if your application is really affected and apply a fix, if there is an issue.

Reference

Pre-requisite

  1. Docker running locally
  2. JDK 8,11
  3. Maven 3.x
  4. Git clone this project
  5. Update spring and spring-boot versions accordingly in pom.xml

Spring boot

Spring MVC

About

POC to prove springshell CVE 2022-22965

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published