Light

Episode #866 Quiz

Spring4Shell
Date: 2022-04-12 | Length: 1.25 hrs | Episode page at twit.tv

About this episode

Spring4Shell became actively exploited, targeting Spring Framework’s DataBinder and servlet-container POST handling, including vulnerable stock sample code. Attackers deployed web shells, malware, and Mirai, while CISA added it to the Known Exploited Vulnerabilities catalog. Mitigations include patching affected Spring, VMware, Cisco products, and avoiding vulnerable JDK9+ configurations.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the initial attack path described by BlueHornet for the reported Nginx issue?
Question 2: What mitigation did Nginx recommend for deployments using the LDAP reference implementation?
Question 3: How did Microsoft describe the ring distribution used by Windows Autopatch?
Question 4: What was the practical risk Steve emphasized about the event-source-polyfill protest-ware change?
Question 5: What detail did Steve cite from Check Point’s reporting on the Spring4Shell outbreak?
Cancel