flawopen.com/Teardowns/cve-2022-22965-spring4shell

● CVE-2022-22965 · CVSS 9.8 · Crítica
Pesquisa · FlawOpen

CVE-2022-22965: Spring4Shell ClassLoader Binding RCE

Análise técnica detalhada e engenharia de mitigação do patch para CVE-2022-22965: Source code teardown of Spring4Shell (CVE-2022-22965): Java BeanWrapper property navigation into Tomcat AccessLogValve to write a webshell to disk.

💡 Explicação em Linguagem Simples (ELI5)

Analogia explicativa: Imagine ordering a customized sandwich online: bread=wheat, cheese=cheddar. But the ordering form lets you type 'kitchen.oven.temperature=5000' and the restaurant's computer blindly adjusts the restaurant's actual kitchen machinery! In Spring4Shell, an attacker used standard HTTP parameters to navigate into the internal Java classloader, telling the web server to create a new log file called 'shell.jsp' and write executable hacker commands into it.

Conceitos Centrais e Termos

Open Source Systems
Componente de arquitetura principal afetado pelo CWE-Security.
CWE-Security
Classificação padrão Common Weakness Enumeration (CWE) para cve-2022-22965-spring4shell.
Defense-in-Depth
Verificação de engenharia em múltiplas camadas e isolamento de limites em tempo de execução.

Análise de Causa Raiz

A causa raiz decorre de parâmetros de limite não validados em sistemas de código aberto, permitindo a dessincronização de estado e a evasão dos controles de segurança.

Fluxo de Ataque Passo a Paso

Step 1

Tomcat Logging Property Binding

Attacker submits HTTP POST parameters targeting Tomcat's class loader: class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell.

Step 2

JSP Extension & Pattern Configuration

Attacker sets the log suffix to .jsp and pattern to an executable JSP webshell snippet.

Step 3

Webshell File Creation

Tomcat's AccessLogValve flushes access logs, creating webapps/ROOT/shell.jsp with executable payload code.

Step 4

Arbitrary Remote Command Execution

Attacker accesses http://victim/shell.jsp?cmd=whoami, executing arbitrary commands with web server privileges.

Código-Fonte: Vulnerável vs. Seguro

✕ IMPLEMENTAÇÃO VULNERÁVEL
// VULNERABLE: Only blocked 'classLoader' directly, missing 'module'
if (Class.class == beanClass && ("classLoader".equals(pd.getName()) || 
    "protectionDomain".equals(pd.getName()))) {
    continue; // Bypassed via class.module.classLoader on Java 9+
}
✓ PATCH SEGURO E ROBUSTO
// FIXED: Strictly restrict all Class property access except 'name'
if (Class.class == beanClass && (!"name".equals(pd.getName()))) {
    continue; // Disallows classLoader, module, and all reflection entry points
}

Lista de Verificação de Segurança para Engenharia