Episode #866 Quiz
Spring4Shell
Date: 2022-04-12 | Length: 1.25 hrs | Episode page at twit.tv
About this episode
Spring4Shell became actively exploited, targeting Spring Framework’s DataBinder and servlet-container POST handling, including vulnerable stock sample code. Attackers deployed web shells, malware, and Mirai, while CISA added it to the Known Exploited Vulnerabilities catalog. Mitigations include patching affected Spring, VMware, Cisco products, and avoiding vulnerable JDK9+ configurations.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.