{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_informational_advisory","csaf_version":"2.1","title":"Java Spring Framework RCE aka Spring4Shell (CVE-2022-22965)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2022-00010","status":"final","version":"34","initial_release_date":"2022-03-30T10:00:00+00:00","current_release_date":"2026-07-28T01:15:42.745325+00:00","revision_history":[{"date":"2022-03-30T10:00:00+00:00","number":"34","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2022-00010"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2022-22965"}],"notes":[{"category":"summary","text":"On 30 March 2022, details were leaked of a Spring Framework RCE that impacts Spring MVC and Spring WebFlux applications running on JDK 9+. The team at Spring released [a blog post](https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement) that documented the vulnerability. The exploit is commonly referenced as Spring4Shell.\n\nSpring listed several conditions necessary to execute the exploit:\n- JDK 9 or higher\n- Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions\n- Tomcat must run on the application as a WAR deployment\n  - Deployed as a standalone Tomcat instance\n- spring-webmvc or spring-webflux dependency\n\nThe conditions listed are only documented known vectors of exploitation and are not limited to that list.\n\nWatchGuard has reviewed all its products and services and so far, has determined that several of the services meet one but not all of the Spring Framework vulnerability requirements. We have yet to confirm exploitation against our products because they do not meet the necessary conditions.","title":"Summary"}]}}