Photo by Sergey Shmidt on Unsplash

Well It’s Spring, and Here’s Spring4Shell

--

Two software frameworks that have a rather poor record for security: Adobe Flash and Java. And so while Adobe Flash has all but disappeared, Java is still causing security problems. A core problem with Java is often its lack of control of the libraries it brings in, and in the difficulty of updating it. And so, Java is on the naughty step again with a new zero-day vulnerability, and which allows for remote code execution (RCE) [CVE-2010–1622]:

The vulnerability has been named “Spring4Shell,” and relates to the SpringSource Spring Framework 2.5.x. Spring is often used as a framework to build Java applications, and does not have a strong record for security with two recent vulnerabilities identified:

At the core of Spring, we have an easy integration of libraries within enterprise solutions, and which allows for an easy deployment…

--

--

Prof Bill Buchanan OBE FRSE
ASecuritySite: When Bob Met Alice

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.