{"id":103660,"date":"2022-03-31T09:36:38","date_gmt":"2022-03-31T07:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah"},"modified":"2022-03-31T09:36:38","modified_gmt":"2022-03-31T07:36:38","slug":"kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","title":{"rendered":"Vulnerabilit\u00e0 critica 0-day in Spring Framework, utilizzato in molti progetti Java","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel modulo Spring Core, incluso nel framework Spring Framework, \u00e8 stata identificata una vulnerabilit\u00e0 critica zero-day che consente a un attaccante remoto non autenticato di eseguire codice sul server. Non \u00e8 ancora chiaro quanto gravi possano essere le conseguenze della vulnerabilit\u00e0 identificata e se gli attacchi saranno altrettanto massicci come nel caso della vulnerabilit\u00e0 in Log4j 2. La vulnerabilit\u00e0 \u00e8 stata soprannominata Spring4Shell, ma non \u00e8 stata ancora assegnata un'identificazione CVE. Nel Spring Framework il problema rimane irrisolto e gi\u00e0 circolano diversi prototipi funzionanti di exploit (1, 2, 3, 4). A rendere la situazione pi\u00f9 grave \u00e8 il fatto che molte applicazioni Java aziendali basate su Spring Framework vengono eseguite con privilegi di root e la vulnerabilit\u00e0 consente di compromettere completamente il sistema.    <\/p>\n<p>Secondo alcune stime, il modulo Spring Core \u00e8 utilizzato nel 74% delle applicazioni Java. Il rischio di vulnerabilit\u00e0 \u00e8 mitigato dal fatto che solo le applicazioni che utilizzano l'annotazione @RequestMapping per connettersi ai gestori delle richieste e il binding dei parametri delle web form nel formato \"name=value\" (POJO, Plain Old Java Object) sono vulnerabili, invece di usare JSON\/XML.      <\/p>\n<p>Quali specifiche applicazioni e framework Java siano colpiti dal problema non \u00e8 ancora chiaro. La vulnerabilit\u00e0 blocca l'aggiunta ai blacklist dei campi \"class\", \"module\" e \"classLoader\" o l'uso di una whitelist esplicita dei campi consentiti. L'exploitation della vulnerabilit\u00e0 \u00e8 possibile solo con Java\/JDK 9 o versioni pi\u00f9 recenti. Il problema \u00e8 causato dalla possibilit\u00e0 di eludere le protezioni della vulnerabilit\u00e0 CVE-2010-1622, corretta nel Spring Framework nel 2010, legata all'esecuzione del gestore classLoader durante l'analisi dei parametri della richiesta.      <\/p>\n<p> Il funzionamento dell'exploit si riduce all'invio di una richiesta con i parametri \"class.module.classLoader.resources.context.parent.pipeline.first.*\", la cui elaborazione porta alla creazione di un file jsp nell'ambiente radice di Apache Tomcat e alla scrittura nel file del codice specificato dall'attaccante. Il file creato diventa accessibile per richieste dirette e pu\u00f2 essere utilizzato come web shell. Per attaccare un'applicazione vulnerabile in un ambiente Apache Tomcat, \u00e8 sufficiente inviare una richiesta con parametri specifici utilizzando lo strumento curl.      curl -v -d \"class.module.classLoader.resources.context.parent.pipeline.first.pattern=codice_da_inserire_nel_file   &amp;class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp   &amp;class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps\/ROOT   &amp;class.module.classLoader.resources.context.parent.pipeline.first.prefix=tomcatwar   &amp;class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat= \"   http:\/\/localhost:8080\/springmvc5-helloworld-exmaple-0.0.1-SNAPSHOT\/rapid7              <\/p>\n<p>Il problema considerato nel Spring Core non deve essere confuso con le vulnerabilit\u00e0 recentemente scoperte CVE-2022-22963 e CVE-2022-22950. Il primo problema riguarda il pacchetto Spring Cloud ed \u00e8 stato corretto nelle versioni 3.1.7 e 3.2.3. Il secondo problema \u00e8 presente in Spring Expression ed \u00e8 stato risolto in Spring Framework 5.3.17. Si tratta di vulnerabilit\u00e0 fondamentalmente diverse. Gli sviluppatori di Spring Framework non hanno ancora rilasciato alcuna dichiarazione sulla nuova vulnerabilit\u00e0 e non hanno pubblicato alcuna correzione.          <\/p>\n<p>Come soluzione temporanea per la protezione, si consiglia di utilizzare nel codice una blacklist di parametri di richiesta non validi:       import org.springframework.core.Ordered;     import org.springframework.core.annotation.Order;     import org.springframework.web.bind.WebDataBinder;     import org.springframework.web.bind.annotation.ControllerAdvice;     import org.springframework.web.bind.annotation.InitBinder;       @ControllerAdvice     @Order(10000)     public class BinderControllerAdvice {        @InitBinder        public void setAllowedFields(WebDataBinder dataBinder) {              String[] denylist = new String[]{\"class.\", \"Class.\", \".class.\", \".Class.\"};              dataBinder.setDisallowedFields(denylist);        }     }<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56941\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435. \u041f\u043e\u043a\u0430 \u043d\u0435 \u044f\u0441\u043d\u043e \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043a\u0430\u0442\u0430\u0441\u0442\u0440\u043e\u0444\u0438\u0447\u043d\u044b \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u043f\u043e\u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0438 \u0431\u0443\u0434\u0443\u0442 \u0430\u0442\u0430\u043a\u0438 \u0441\u0442\u043e\u043b\u044c \u0436\u0435 \u043c\u0430\u0441\u0441\u043e\u0432\u044b\u043c\u0438, \u043a\u0430\u043a \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u0432 Log4j 2. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Spring4Shell, \u043d\u043e CVE-\u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440 \u043f\u043e\u043a\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103660","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Spring Framework, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 Java-\u043f\u0440\u043e\u0435\u043a\u0442\u0430\u0445 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-03-31T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-03-31T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 critica zero-day nel Spring Framework, utilizzato in molti progetti Java | ProHoster","description":"Nel modulo Spring Core, fornito con il framework Spring Framework, \u00e8 stata identificata una vulnerabilit\u00e0 critica zero-day, che consente a un attaccante remoto non autenticato di eseguire il proprio codice sul server.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Spring Framework, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 Java-\u043f\u0440\u043e\u0435\u043a\u0442\u0430\u0445 | ProHoster","og:description":"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-03-31T07:36:38+00:00","article:modified_time":"2022-03-31T07:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103660","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-03-31 07:37:59","updated":"2022-09-27 15:24:59","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=103660"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103660\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=103660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=103660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=103660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}