
CVE-2022-22965 Spring4Shell: Spring Framework RCE
CVE-2022-22965 (Spring4Shell) is a critical remote code execution vulnerability in the Spring Framework's data binding component. By manipulating HTTP request parameters to abuse Java's ClassLoader mechanism, an attacker can write a JSP web shell to a Tomcat-served directory and achieve persistent remote code execution. Affects Spring Framework 5.3.x before 5.3.18 and 5.2.x before 5.2.20 running on JDK 9+.


