{"id":13157,"date":"2022-04-01T16:11:20","date_gmt":"2022-04-01T14:11:20","guid":{"rendered":"http:\/\/nfirjun2026.local\/nfir-threat-intelligence-report-indications-that-vulnerability-spring4shell-cve-2022-22965-may-be-actively-exploited\/"},"modified":"2024-02-12T14:19:46","modified_gmt":"2024-02-12T13:19:46","slug":"nfir-threat-intelligence-report-indications-that-vulnerability-spring4shell-cve-2022-22965-may-be-actively-exploited","status":"publish","type":"post","link":"https:\/\/www.cyber-security-online.nl\/en\/nfir-threat-intelligence-report-indications-that-vulnerability-spring4shell-cve-2022-22965-may-be-actively-exploited\/","title":{"rendered":"NFIR Threat Intelligence Report &#8211; Indications that vulnerability Spring4Shell (CVE-2022-22965) may be actively exploited"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"13157\" class=\"elementor elementor-13157 elementor-8764\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-06c4724 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"06c4724\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fb77167\" data-id=\"fb77167\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-cca9d26 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cca9d26\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-b11f1dc\" data-id=\"b11f1dc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ef559c8 elementor-widget elementor-widget-heading\" data-id=\"ef559c8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Description<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1234310 elementor-widget elementor-widget-text-editor\" data-id=\"1234310\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Spring Core Framework is a collection of Java software libraries that can be used  <br \/>in software programs written in Java. Spring Core is embedded in many Java software.  <br \/>This vulnerability allows an attacker &#8211; without required authentication<br \/>can execute unauthorized code in certain circumstances and gain access to the  <br \/>program or application and its associated information.  <span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">To be able to abuse this vulnerability, there are currently several technical  <\/span><span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">prerequisites known. These are listed below. It is possible that this list is not currently complete.  <\/span><\/p>\n<p>As far as clear, the application is vulnerable if it meets the following conditions:<\/p>\n<ul>\n<li>Uses Spring Core Framework (up to and including version 5.3.17);<\/li>\n<li>Uses spring-webmvc or spring-webflux dependencies (unconfirmed);<\/li>\n<li>Uses form bindings with &#8220;name=value&#8221; data;<\/li>\n<li>Does not use an allow list or denylist where the use of specific fields  <br \/>is excluded (i.e. &#8220;class&#8221;, &#8220;module&#8221; and &#8220;classLoader&#8221;);<\/li>\n<li>Runs on Java version 9 (JDK) or higher.<\/li>\n<\/ul>\n<p>In short, applications that can be accessed remotely, process user input and Spring  <br \/>Core Framework (a version lower than 5.3.17) to handle these inputs are possible  <br \/>vulnerable.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-f4bff09\" data-id=\"f4bff09\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-996aa7a elementor-widget elementor-widget-image\" data-id=\"996aa7a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"800\" height=\"600\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/spring4shell_nfir.jpg\" class=\"attachment-full size-full wp-image-8814\" alt=\"NFIR Threat Intelligence Report - Indications that Spring4Shell vulnerability (CVE-2022-22965) may be actively abused\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/spring4shell_nfir.jpg 800w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/spring4shell_nfir-300x225.jpg 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/spring4shell_nfir-768x576.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-49b2fd5 elementor-widget elementor-widget-button\" data-id=\"49b2fd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/NFIR-Threat-Intelligence-Report-Indicaties-dat-kwetsbaarheid-Spring4Shell-CVE-2022-22965-mogelijk-actief-misbruikt-wordt.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download Threat Intelligence Report - Indications that vulnerability Spring4Shell (CVE-2022-22965) may be actively exploited here<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-51b2e11 elementor-widget elementor-widget-button\" data-id=\"51b2e11\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/en\/this-spring4shell-flow-chart-helps-you-make-the-right-decisions\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-sitemap\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">This Spring4Shell flow chart helps you make the right decisions<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a2565af elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a2565af\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-73bc578\" data-id=\"73bc578\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4c7047c nfir-from-uael-faq nfir-faq-schema elementor-widget elementor-widget-accordion\" data-id=\"4c7047c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-8011\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-8011\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What potential impact does the Spring4Shell vulnerability have?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-8011\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-8011\"><p>If an attacker is able to successfully exploit the vulnerability, it can lead to the execution of unauthorized code on the affected systems. This could potentially result in compromising the server the application is running on. This attack can be executed from the Internet without requiring authentication. From a compromised server, an attacker could potentially gain access to the rest of the network. For this reason, the CVSS vulnerability score was classified as critical (9.8).<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-8012\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-8012\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What are the indicators of abuse of the Spring4Shell vulnerability?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-8012\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-8012\"><p>At the time of writing, there are multiple indicators that there are active attempts to exploit the Spring4Shell vulnerability &#8211; including attempts to exploit the vulnerability by known rogue IP addresses.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-8013\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-8013\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How is the Spring4Shell vulnerability detectable?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-8013\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-8013\"><p>Because the vulnerable functionality resides in a popular Java software library, the current scope or impact is not transparent. It is very likely that many used applications are vulnerable. It is not currently known for a number of applications whether they fall into the vulnerable category. As a result, detecting any form of abuse is a complex matter.<\/p><p>However, a scanner has been published that may be able to detect the presence of the Spring Framework on (local) systems. This scanner is published via the code platform GitHub:<br><a href=\"https:\/\/github.com\/hillu\/local-spring-vuln-scanner\">https:\/\/github.com\/hillu\/local-spring-vuln-scanner<\/a><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-8014\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-8014\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What are the recommendations regarding the Spring4Shell vulnerability?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-8014\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-8014\"><p>For developers of applications using Spring Framework, the following advice applies:<br>A new version of Spring Framework is available for download at the URL. In addition, it is recommended to at least update to Spring Framework version 5.3.18 (with Spring Boot 2.6.6 or 2.5.12) or Spring Framework 5.2.20.<br>In doing so, NFIR recommends upgrading as soon as possible and then rolling it out to the affected systems and applications.<\/p><p><em>At the time when upgrading is not possible, the following two mitigations can be applied:<\/em><\/p><ol><li>For organizations that use Spring Framework itself and have specific bindings within applications that use non-standard data types, it is important to specify the allowed fields that the application may use &#8211; Learn More<br>is available in the Spring documentation: <a href=\"https:\/\/docs.spring.io\/spring-framework\/docs\/current\/javadoc-api\/org\/springframework\/validation\/DataBinder.html#:~:text=fields%20when%20binding.-,setAllowedFields,-public%C2%A0void%C2%A0setAllowedFields\">DataBinder (Spring Framework 5.3.18 API)<\/a><p>2. A second available mitigation (in the case that Tomcat is used as the underlying web server) involves updating Tomcat to version 10.0.20, 9.0.62, and 8.5.78 (or higher)<br>with which the attack route via Tomcat no longer functions. More information is available on the Spring website: <a href=\"https:\/\/spring.io\/blog\/2022\/04\/01\/spring-framework-rce-mitigation-alternative\">Spring Framework RCE, Mitigation Alternative<\/a><\/p><\/li><\/ol><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-8015\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-8015\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Is there an action plan that your organization can follow?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-8015\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-8015\"><p>It is important for your organization to take at least the following steps:<\/p><ol><li>Map out which individual vendors you have for on-premises software packages, Software-as-a-Service (SaaS) or other application vendors;<\/li><li>Consult your vendor&#8217;s website and determine if there are some form of &#8216;dependency lists&#8217; available within which you can verify that &#8216;Spring Framework&#8217; is being used within  <br>the application;<\/li><li>Contact your vendors to verify if &#8216;Spring Framework&#8217; is used within the applications and which version of Spring Framework is used;<\/li><li>Prepare your organization for the situation when patches need to be executed unexpectedly (possibly outside the regular update timeframes) and apply patches in a controlled manner according to your organization&#8217;s usual procedure.<\/li><\/ol><p>Do you have systems where the risk is high, for example, systems with sensitive or special personal data? If so, do you have any possible indications that Java is being used with Spring Framework and updates are not yet available? Then consider temporarily disabling the system.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-8016\" class=\"elementor-tab-title\" data-tab=\"6\" role=\"button\" aria-controls=\"elementor-tab-content-8016\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What should your organization do in case of potential abuse?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-8016\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"6\" role=\"region\" aria-labelledby=\"elementor-tab-title-8016\"><p>If your organization is suspected of having been the victim of an attack, it is strongly recommended that you have an investigation carried out into the cause of the attack, the extent to which attackers may have compromised other systems and what information may have been accessed without authorisation.<\/p><ol><li>If possible, disconnect affected systems from the network, but leave them on (because of possible traces such as volatile memory &#8211; RAM);<\/li><li>Have the affected systems forensically examined; ensure adequate backups;<\/li><li>Reset your passwords and user data;<\/li><li>Report to the Police;<\/li><li>Consider filing a report with the Personal Data Authority.<\/li><\/ol><p>Does your organization currently have an incident? Our Computer Emergency Response Teams (CERT) are available to organizations 24\/7 to support IT Security Incidents.<\/p><p>Then call<a href=\"tel:+31881330700\"> 088 133 0700<\/a> and we will do our utmost to help you as quickly as possible.<a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\" data-mil=\"6730\">(Learn more about our Incident Response Service.<\/a>)<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-40aad01 elementor-widget elementor-widget-text-editor\" data-id=\"40aad01\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Does your organization currently have an incident? Our Computer Emergency Response Teams (CERT) are available to organizations 24\/7 to support IT Security Incidents.<\/p>\n<p>Then call<a href=\"tel:+31881330700\"> 088 133 0700<\/a> and we will do our best to help you as soon as possible. Here you will find more <a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\" data-wplink-edit=\"true\">information about our Incident Response <\/a>service.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2dfe00a elementor-widget elementor-widget-button\" data-id=\"2dfe00a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/NFIR-Threat-Intelligence-Report-Indicaties-dat-kwetsbaarheid-Spring4Shell-CVE-2022-22965-mogelijk-actief-misbruikt-wordt.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download Threat Intelligence Report - Indications that vulnerability Spring4Shell (CVE-2022-22965) may be actively exploited here<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5419f76 elementor-widget elementor-widget-text-editor\" data-id=\"5419f76\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>Disclaimer: NFIR has made every effort to make this information accurate and reliable. However, the information provided is without any guarantee of any kind and its use is entirely at the risk of the user. NFIR assumes no responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided.<\/em><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>The Spring Core Framework vulnerability (CVE-2022-22965) allows attackers to execute unauthorized code and gain access to systems without required authentication.<\/p>\n","protected":false},"author":4,"featured_media":8814,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"Spring Core Framework Vulnerability (CVE-2022-22965): Spring4Shell Active Misuse? | NFIR","_seopress_titles_desc":"Find out what you can do to mitigate vulnerabilities within the Spring4Shell framework. Read the Threat Intelligence Report, download the scanner and view indicators of abuse. If so, take action and mitigate vulnerabilities to malware attacks.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"none","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[29,51],"tags":[],"class_list":["post-13157","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media-en","category-threat-intelligence-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/13157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=13157"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/13157\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media\/8814"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=13157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/categories?post=13157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/tags?post=13157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}