flawopen.com/Teardowns/cve-2022-22965-spring4shell

● CVE-2022-22965 · CVSS 9.8 · 严重
安全研究 · FlawOpen

深度技术拆解:CVE-2022-22965: Spring4Shell ClassLoader Binding RCE

CVE-2022-22965 源代码级技术深度解析与系统加固工程指南:深入剖析漏洞触发条件、攻击利用链条与加固补丁的具体实现。

💡 通俗易懂的原理解析 (ELI5)

通俗原理解析:Imagine ordering a customized sandwich online: bread=wheat, cheese=cheddar. But the ordering form lets you type 'kitchen.oven.temperature=5000' and the restaurant's computer blindly adjusts the restaurant's actual kitchen machinery! In Spring4Shell, an attacker used standard HTTP parameters to navigate into the internal Java classloader, telling the web server to create a new log file called 'shell.jsp' and write executable hacker commands into it.

核心概念与专有名词

Open Source Systems
技术概念 (Open Source Systems):Core architecture component affected by CWE-Security.
CWE-Security
技术概念 (CWE-Security):Standard Common Weakness Enumeration classification for cve-2022-22965-spring4shell.
Defense-in-Depth
技术概念 (Defense-in-Depth):Multi-layered engineering verification and runtime boundary isolation.

根本原因剖析 (Root Cause)

根本原因在于开源系统中未经验证的边界参数,导致状态不同步并绕过安全控制。

攻击执行流程分解

Step 1

Tomcat Logging Property Binding

Attacker submits HTTP POST parameters targeting Tomcat's class loader: class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell.

Step 2

JSP Extension & Pattern Configuration

Attacker sets the log suffix to .jsp and pattern to an executable JSP webshell snippet.

Step 3

Webshell File Creation

Tomcat's AccessLogValve flushes access logs, creating webapps/ROOT/shell.jsp with executable payload code.

Step 4

Arbitrary Remote Command Execution

Attacker accesses http://victim/shell.jsp?cmd=whoami, executing arbitrary commands with web server privileges.

源代码对比:漏洞与安全实现

✕ 存在漏洞的实现
// VULNERABLE: Only blocked 'classLoader' directly, missing 'module'
if (Class.class == beanClass && ("classLoader".equals(pd.getName()) || 
    "protectionDomain".equals(pd.getName()))) {
    continue; // Bypassed via class.module.classLoader on Java 9+
}
✓ 加固后的安全修复
// FIXED: Strictly restrict all Class property access except 'name'
if (Class.class == beanClass && (!"name".equals(pd.getName()))) {
    continue; // Disallows classLoader, module, and all reflection entry points
}

工程与系统安全加固清单