Help Center> Cloud Firewall> FAQs> Troubleshooting> How Does CFW Detect and Defend Against Attacks Exploiting the Spring Framework Remote Code Execution Vulnerability?
Updated on 2022-10-31 GMT+08:00

How Does CFW Detect and Defend Against Attacks Exploiting the Spring Framework Remote Code Execution Vulnerability?

Spring Framework is a lightweight open-source application framework for developing enterprise Java applications. A remote code execution vulnerability (CVE-2022-22965) was disclosed in the Spring framework and classified as critical. This vulnerability can be exploited to attack Java applications running on JDK 9 or later versions.

CFW can detect and intercept attacks that exploit the Spring Framework remote code execution vulnerability.

Vulnerability Name

Spring Framework remote code execution vulnerability

Affected Versions

  • JDK 9 or later
  • Applications developed using the Spring Framework or derived framework

Mitigation

  1. Log in to the CFW console and perform the following operations:

    1. Purchase the CFW standard edition. For details, see Purchasing CFW.
    2. Enable Basic protection on the Intrusion Prevention page and set Action to Block. For details, see Configuring Intrusion Prevention.

Troubleshooting FAQs

more