Skip to content

Comment on A Technical Analysis of How Spring4Shell (CVE-2022-22965) Works

Comments

That's a good technical write-up. I wonder how much of an issue this CVE will be compared to Log4Shell....

cwsOP

Depends a lot on how many Spring apps out there have the prereqs to be vulnerable. The widespread nature of Log4Shell is what made it “worse” than other RCE vulns. I don’t have a sense of how many vulnerable instances of this one might be out there but the number could be enormous.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.