Spring Framework 'class.classLoader' Code Injection Vulnerability
BID:40954
Info
Spring Framework 'class.classLoader' Code Injection Vulnerability
| Bugtraq ID: | 40954 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1622 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2010 12:00AM |
| Updated: | Nov 03 2015 08:04PM |
| Credit: | Meder Kydyraliev, Google Security Team |
| Vulnerable: |
SpringSource Spring Framework 3.0.2 SpringSource Spring Framework 3.0.1 SpringSource Spring Framework 3.0 SpringSource Spring Framework 2.6.6 SpringSource Spring Framework 2.5.7 SpringSource Spring Framework 2.5.6 SpringSource Spring Framework 2.5.6 SpringSource Spring Framework 2.5.5 SpringSource Spring Framework 2.5.5 SpringSource Spring Framework 2.5.4 SpringSource Spring Framework 2.5.4 SpringSource Spring Framework 2.5.3 SpringSource Spring Framework 2.5.3 SpringSource Spring Framework 2.5.2 SpringSource Spring Framework 2.5.2 SpringSource Spring Framework 2.5.1 SpringSource Spring Framework 2.5.1 SpringSource Spring Framework 2.5 SpringSource Spring Framework 2.5 Red Hat JBoss Web Framework Kit for RHEL 5 Server 1.0.0 Red Hat JBoss Web Framework Kit for RHEL 4 ES 5.0.0 Red Hat JBoss Web Framework Kit for RHEL 4 AS 5.0.0 Apache Software Foundation Geronimo 2.1.5 Apache Software Foundation Geronimo 2.1.4 Apache Software Foundation Geronimo 2.1.3 Apache Software Foundation Geronimo 2.1.2 Apache Software Foundation Geronimo 2.1.1 Apache Software Foundation Geronimo 2.1 |
| Not Vulnerable: |
SpringSource Spring Framework 3.0.3 SpringSource Spring Framework 2.5.7 SR1 (Subscript SpringSource Spring Framework 2.5.6.SEC02 Apache Software Foundation Geronimo 2.1.6 |
Discussion
Spring Framework 'class.classLoader' Code Injection Vulnerability
Spring Framework is prone to a remote code-injection vulnerability.
An attacker can exploit this issue to inject and execute arbitrary malicious Java code within the context of the affected application. Successful exploits will compromise the affected application and the underlying system; other attacks are also possible.
Versions of Spring Framework prior to 3.03, 2.5.6.SEC02, and 2.5.7.SR01 are vulnerable.
Spring Framework is prone to a remote code-injection vulnerability.
An attacker can exploit this issue to inject and execute arbitrary malicious Java code within the context of the affected application. Successful exploits will compromise the affected application and the underlying system; other attacks are also possible.
Versions of Spring Framework prior to 3.03, 2.5.6.SEC02, and 2.5.7.SR01 are vulnerable.
Exploit / POC
Spring Framework 'class.classLoader' Code Injection Vulnerability
An attacker can use readily available tools to exploit this vulnerability.
An attacker can use readily available tools to exploit this vulnerability.
Solution / Fix
Spring Framework 'class.classLoader' Code Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Spring Framework 'class.classLoader' Code Injection Vulnerability
References:
References:
- 17 June 2010: CVE-2010-1622: Spring Framework execution of arbitrary code (SpringSource)
- Apache Geronimo v2.1.6 (Apache Software Foundation)
- Spring - Homepage (SpringSource)
- CVE-2010-1622: Spring Framework execution of arbitrary code (s2-security
)