flawopen.com/Teardowns/cve-2022-22965-spring4shell

● CVE-2022-22965 · CVSS 9.8 · Критический
Исследования · FlawOpen

Технический разбор: CVE-2022-22965: Spring4Shell ClassLoader Binding RCE

Технический анализ исходного кода и защитные инженерные меры для CVE-2022-22965: Source code teardown of Spring4Shell (CVE-2022-22965): Java BeanWrapper property navigation into Tomcat AccessLogValve to write a webshell to disk.

💡 Простыми словами (ELI5)

Наглядная аналогия: Imagine ordering a customized sandwich online: bread=wheat, cheese=cheddar. But the ordering form lets you type 'kitchen.oven.temperature=5000' and the restaurant's computer blindly adjusts the restaurant's actual kitchen machinery! In Spring4Shell, an attacker used standard HTTP parameters to navigate into the internal Java classloader, telling the web server to create a new log file called 'shell.jsp' and write executable hacker commands into it.

Ключевые понятия и термины

Open Source Systems
Технический термин (Open Source Systems): Core architecture component affected by CWE-Security.
CWE-Security
Технический термин (CWE-Security): Standard Common Weakness Enumeration classification for cve-2022-22965-spring4shell.
Defense-in-Depth
Технический термин (Defense-in-Depth): Multi-layered engineering verification and runtime boundary isolation.

Анализ первопричины

Основная причина заключается в невалидированных граничных параметрах в системах с открытым исходным кодом, что приводит к рассинхронизации состояний и обходу средств безопасности.

Пошаговый сценарий атаки

Step 1

Tomcat Logging Property Binding

Attacker submits HTTP POST parameters targeting Tomcat's class loader: class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell.

Step 2

JSP Extension & Pattern Configuration

Attacker sets the log suffix to .jsp and pattern to an executable JSP webshell snippet.

Step 3

Webshell File Creation

Tomcat's AccessLogValve flushes access logs, creating webapps/ROOT/shell.jsp with executable payload code.

Step 4

Arbitrary Remote Command Execution

Attacker accesses http://victim/shell.jsp?cmd=whoami, executing arbitrary commands with web server privileges.

Исходный код: Уязвимый vs Защищённый вариант

✕ УЯЗВИМАЯ РЕАЛИЗАЦИЯ
// VULNERABLE: Only blocked 'classLoader' directly, missing 'module'
if (Class.class == beanClass && ("classLoader".equals(pd.getName()) || 
    "protectionDomain".equals(pd.getName()))) {
    continue; // Bypassed via class.module.classLoader on Java 9+
}
✓ БЕЗОПАСНЫЙ ИСПРАВЛЕННЫЙ ВАРИАНТ
// FIXED: Strictly restrict all Class property access except 'name'
if (Class.class == beanClass && (!"name".equals(pd.getName()))) {
    continue; // Disallows classLoader, module, and all reflection entry points
}

Чек-лист по защите системы для инженеров