TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A Technical Analysis of How Spring4Shell (CVE-2022-22965) Works

14 点作者 cws大约 3 年前

5 条评论

alipitch大约 3 年前
Are there any data binding libraries (deserialization, marshaling, pickling libraries) that do not have the class of weaknesses as the two CVEs (CVE-2022-22965, CVE-2010-1622)?<p>If there are any for Java, can they be used with Spring Boot (Spring Framework)? Maybe there are some for in another programming language?
ajdenver大约 3 年前
I&#x27;ve been told it can be hard to know if vendor-built apps in your environment are using Spring. What are some apps built on this platform?
PeekPoke大约 3 年前
That&#x27;s a good technical write-up. I wonder how much of an issue this CVE will be compared to Log4Shell....
评论 #30870775 未加载
cws大约 3 年前
This is about CVE-2022-22965. Maybe I’ll edit the title to reflect that.
评论 #30870804 未加载
rpple大约 3 年前
Whether or not this turns out to have the same blast radius and Log4Shell, it has certainly captured a lot of attention. Lots and lots of folks using Tomcat...