Dissecting the Spring4Shell vulnerability. [Research Saturday]

Published: June 18, 2022, 7 a.m.

Edward Wu, senior principal data scientist at ExtraHop, joins Dave to discuss the company's research, "A Technical Analysis of How Spring4Shell Works." ExtraHop first noticed chatter from social media in March of 2022 on a new remote code execution (RCE) vulnerability and immediately started tracking the issue.\nIn the research, it describes how the exploit works and breaks down how the ExtraHop team came to identify the Spring4Shell vulnerability. The research describes the severity of the vulnerability, saying, "The impact of an RCE in this framework could have a serious impact similar to Log4Shell."\nThe research can be found here:\nHow the Spring4Shell Zero-Day Vulnerability Works\n\nLearn more about your ad choices. Visit megaphone.fm/adchoices