flawopen.com/Teardowns/cve-2022-22965-spring4shell

● CVE-2022-22965 · CVSS 9.8 · Kritis
Riset Keamanan · FlawOpen

CVE-2022-22965: Spring4Shell ClassLoader Binding RCE

Analisis teknis mendalam dan mitigasi rekayasa sistem untuk CVE-2022-22965: Source code teardown of Spring4Shell (CVE-2022-22965): Java BeanWrapper property navigation into Tomcat AccessLogValve to write a webshell to disk.

💡 Penjelasan Sederhana (ELI5)

Analogi dunia nyata: Imagine ordering a customized sandwich online: bread=wheat, cheese=cheddar. But the ordering form lets you type 'kitchen.oven.temperature=5000' and the restaurant's computer blindly adjusts the restaurant's actual kitchen machinery! In Spring4Shell, an attacker used standard HTTP parameters to navigate into the internal Java classloader, telling the web server to create a new log file called 'shell.jsp' and write executable hacker commands into it.

Konsep Kunci & Istilah

Open Source Systems
Komponen arsitektur utama yang terpengaruh oleh CWE-Security.
CWE-Security
Klasifikasi standar Common Weakness Enumeration (CWE) untuk cve-2022-22965-spring4shell.
Defense-in-Depth
Verifikasi rekayasa berlapis dan isolasi batas waktu proses (runtime).

Analisis Akar Masalah (Root Cause)

Akar masalah bermula dari parameter batas yang tidak divalidasi pada sistem open source, yang memungkinkan desinkronisasi status dan bypass kontrol keamanan.

Alur Serangan Langkah demi Langkah

Step 1

Tomcat Logging Property Binding

Attacker submits HTTP POST parameters targeting Tomcat's class loader: class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell.

Step 2

JSP Extension & Pattern Configuration

Attacker sets the log suffix to .jsp and pattern to an executable JSP webshell snippet.

Step 3

Webshell File Creation

Tomcat's AccessLogValve flushes access logs, creating webapps/ROOT/shell.jsp with executable payload code.

Step 4

Arbitrary Remote Command Execution

Attacker accesses http://victim/shell.jsp?cmd=whoami, executing arbitrary commands with web server privileges.

Kode Sumber: Rentan vs Aman

✕ IMPLEMENTASI RENTAN
// VULNERABLE: Only blocked 'classLoader' directly, missing 'module'
if (Class.class == beanClass && ("classLoader".equals(pd.getName()) || 
    "protectionDomain".equals(pd.getName()))) {
    continue; // Bypassed via class.module.classLoader on Java 9+
}
✓ PERBAIKAN AMAN & KUAT
// FIXED: Strictly restrict all Class property access except 'name'
if (Class.class == beanClass && (!"name".equals(pd.getName()))) {
    continue; // Disallows classLoader, module, and all reflection entry points
}

Daftar Periksa Penguatan Sistem Rekayasa