Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

IIIIIuhrey/SpringCore0day

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

8 Commits

Repository files navigation

Spring Core RCE

继 Spring Cloud 之后,3.29 日 ,网上爆出Spring 的又一重量级漏洞:Spring Core RCE

流传的打码poc

目前exp 已上传 exp.py
流传的打码poc
尴尬的局面

Spring 官方补丁也正在积极的赶制中

Spring 制作中的补丁链接

漏洞影响

  1. jdk 版本在9及以上的
  2. 使用了Spring Framework或衍生框架

漏洞修复建议

目前,Spring 官方暂未发布补丁,建议降低jdk 版本作为临时方案

About

SpringCore0day from https://share.vx-underground.org/

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 100.0%

AltStyle によって変換されたページ (->オリジナル) /