flawopen.com/Teardowns/CVE-2022-22965 Spring4Shell
Imagine ordering a customized sandwich online: bread=wheat, cheese=cheddar. But the ordering form lets you type 'kitchen.oven.temperature=5000' and the restaurant's computer blindly adjusts the restaurant's actual kitchen machinery! In Spring4Shell, an attacker used standard HTTP parameters to navigate into the internal Java classloader, telling the web server to create a new log file called 'shell.jsp' and write executable hacker commands into it.
class.module.classLoaderSpring MVC automatically binds HTTP parameters to Java Beans. While Spring previously blocked class.classLoader, JDK 9 introduced Java Modules. Attackers bypassed the check by traversing class.module.classLoader, reaching Tomcat's AccessLogValve and changing its file prefix to shell.jsp and writing JSP code directly into web directories.
// VULNERABLE: Only blocked 'classLoader' directly, missing 'module'
if (Class.class == beanClass && ("classLoader".equals(pd.getName()) ||
"protectionDomain".equals(pd.getName()))) {
continue; // Bypassed via class.module.classLoader on Java 9+
}
// FIXED: Strictly restrict all Class property access except 'name'
if (Class.class == beanClass && (!"name".equals(pd.getName()))) {
continue; // Disallows classLoader, module, and all reflection entry points
}
class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell..jsp and pattern to an executable JSP webshell snippet.:webapps/ROOT/shell.jsp and writes the payload into it.:http://victim/shell.jsp?cmd=whoami, executing arbitrary commands with web server privileges.@InitBinder or DataBinder.setAllowedFields().