WAF mitigation for Spring Framework RCE CVE-2022-22965

Last updated on April 1, 2022
ZeroDay-RCE-CVE-2022-22965.jpg

Vulnerability

Spring Framework is an open source lightweight J2EE application development Framework, which provides IOC, AOP, MVC and other functions. It can solve common problems encountered by programmers, and improve application development convenience and software system construction efficiency.

The vulnerability impacts Spring MVC and Spring WebFlux applications on JDK 9+. The specific exploit requires the application to run on Tomcat as a WAR deployment. If deployed as a Spring Boot executable jar (the default), it is not vulnerable.

Requirements for the specific scenario:

  • JDK 9 or higher
  • Apache Tomcat as the Servlet container
  • Packaged as a traditional WAR (as opposed to a Spring Boot executable jar)
  • spring-webmvc or spring-webflux dependency
  • Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions

The vulnerability is more general, and other exploit methods may exist but remain unreported.

Vulnerability Details:

  • Vulnerability level: High Risk

  • Affected version:
    Spring Framework 5.3.x < 5.3.18
    Spring Framework 5.2.x < 5.2.20

  • Security version:
    Spring Framework = 5.3.18
    Spring Framework = 5.2.20

Suggested Workarounds

Upgrade the Spring Framework to 5.3.18, 5.2.20 or later versions.

CDNetworks Deployed New Rules to Mitigate Spring Framework RCE

CDNetworks security team responded to this high-risk vulnerability, deploying new WAF rules (9801, 9802, 9803) for their systems to mitigate the Zero Day CVE on March 31, 2022.

Customers using Cloud Security or Web Application Firewall will receive updates of new rules (9801, 9802, 9803) and enable Block Mode to detect CVE-2022-22965 exploit attempts.

Rule ID Rule Name Attack Type Action
9803 Spring4shell_3 3rd Party Component Exploit Block
9802 Spring4shell_2 3rd Party Component Exploit Block
9801 Sping4shell_1 3rd Party Component Exploit Block

Reference: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

More To Explore

Web Performance

Top 7 CDN Providers for Asia in 2026

Compare the top CDN providers for Asia in 2026, including Cloudflare, Akamai, CDNetworks, CloudFront, Fastly, Tencent, and Alibaba.

Read More »
Cloud Security

State of WAAP Report 2025: What AI Is Changing About Web App and API Security

Uncover key insights from the State of WAAP Report 2025 and see what AI is changing about web app and API security,

Read More »