{"id":220,"date":"2022-05-05T22:44:00","date_gmt":"2022-05-05T22:44:00","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=220"},"modified":"2024-01-08T20:54:53","modified_gmt":"2024-01-08T20:54:53","slug":"one-month-in-cycognito-looks-at-spring4shell","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/","title":{"rendered":"One month in: CyCognito looks at Spring4Shell"},"content":{"rendered":"\n<p>It\u2019s likely by now that you are aware of Spring4Shell, a vulnerability in the Spring framework that permits remote code execution (RCE) and was publicly disclosed on March 30th, 2022.&nbsp;<\/p>\n\n\n\n<p>NIST assigned Spring4Shell a score of 9.8, presumably out of concern of a similar blast radius to Log4Shell, which was trivial to exploit and very common. With 6 out of 10 Java developers reporting using the Spring framework (<a href=\"https:\/\/snyk.io\/blog\/spring-dominates-the-java-ecosystem-with-60-using-it-for-their-main-applications\/\" target=\"_blank\" rel=\"noreferrer noopener\">Snyk research, 2020<\/a>), this vulnerability jumped quickly to the headlines.&nbsp;<\/p>\n\n\n\n<p>On the outside this appears to be a nightmare; a critical RCE on a widely used web application framework in a current version.&nbsp;<\/p>\n\n\n\n<p>But is it?<\/p>\n\n\n\n<p><em>[For more information on Spring4Shell, please see our\u00a0<\/em><a href=\"\/blog\/detecting-and-validating-spring4shell-vulnerability-cve-2022-22965\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>April 6th blog post<\/em><\/a><em>]<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The importance of rapid visibility to risk<\/strong><\/h2>\n\n\n\n<p>Time is of the essence when any vulnerability is disclosed but is especially important with critical severity vulnerabilities like Spring4Shell. Response windows are tight \u2013 the majority of CVEs start to be exploited&nbsp;<a href=\"https:\/\/www.cisa.gov\/binding-operational-directive-22-01\" target=\"_blank\" rel=\"noreferrer noopener\">within hours or days of disclosure<\/a>, according to the Cybersecurity &amp; Infrastructure Security Agency (CISA):<\/p>\n\n\n\n<p><em>&#8220;&#8230;threat actors are extremely fast to exploit their vulnerabilities of choice: of those 4% of known exploited CVEs, 42% are being used on day 0 of disclosure; 50% within 2 days; and 75% within 28 days!&#8221;.<\/em><\/p>\n\n\n\n<p>Unfortunately this is a catch-22 scenario for many security teams. They understand the importance of rapid response but without visibility into their entire attack surface they can\u2019t understand vulnerability relevance. The act of response is necessary to quantify the risk to their organization. This equates to a constant fire drill for many IT security teams, contributing to uncertain prioritization and resource burnout.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Spring4Shell data from CyCognito research<\/strong><\/h2>\n\n\n\n<p>CyCognito began tracking Spring4Shell (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-22965\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-22965<\/a>) immediately after disclosure. We examined attack surface scan results and quantified the number of customer assets using the Spring framework. We then cross referenced the assets running Spring with version and system information to understand the number vulnerable to the Spring4Shell exploit.<\/p>\n\n\n\n<p>Our results? Out of nearly 4,000 assets discovered running Spring,&nbsp;<em>less than 1%<\/em>&nbsp;were vulnerable to the Spring4Shell exploit.&nbsp;<strong>This was great news for our customers<\/strong>&nbsp;\u2013 with this information they were able to quickly understand external risk posture and communicate it across all levels of their organization.&nbsp;<\/p>\n\n\n\n<p>We were initially surprised at this result considering the number of assets CyCognito monitors across many industries; software development, manufacturing, telecommunications, energy, and more. As a data company, the \u201cwhy\u201d is as important as the \u201cwhat\u201d, and with that in mind we determined multiple explanations that may occur to an outsider:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CyCognito customers respond more efficiently to emergency patches (mature playbooks, etc.)<\/li>\n\n\n\n<li>Sample size targeted the wrong demographic or was not large enough<\/li>\n\n\n\n<li>CyCognito testing had errors<\/li>\n\n\n\n<li>Spring4Shell exploitable systems are rare<\/li>\n<\/ul>\n\n\n\n<p>While some CyCognito customers will naturally&nbsp;respond more efficiently to emergency patches than others, it\u2019s not likely across our entire sample set. Same response regarding the wrong demographic and size; possible but not likely. Now, regarding CyCognito testing, error is not possible with multiple verification passes, both human and automated.<\/p>\n\n\n\n<p>Our conclusion is that the fourth option, exploitable systems are rare, is the reality. A review of NIST description for Spring4Shell provides some color to the moon alignment that must happen for a system to be exploitable:<\/p>\n\n\n\n<p><em>\u201cA Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit.\u201d<\/em><\/p>\n\n\n\n<p>A recent update to a&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/04\/04\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Spring4Shell blog<\/a>&nbsp;reports Microsoft has also observed a low volume of exploit attempts for these vulnerabilities across their cloud services.<\/p>\n\n\n\n<p>Why is this conclusion important? Let&#8217;s compare Log4Shell and Spring4Shell next.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Log4Shell and Spring4Shell&nbsp;<\/strong><\/h2>\n\n\n\n<p>Log4Shell is a vulnerability in the Apache Log4j framework that permits arbitrary code execution. Hundreds of millions of systems use log4j as a means to interact with adjacent systems and the vulnerability enabled a jump off point to access internal data.<\/p>\n\n\n\n<p>Spring4Shell is a vulnerability in a programming and configuration framework for developing Java applications. Most of the systems using Spring framework are internal corporate apps that cannot be scanned or accessed from the &#8220;outside world&#8221; &#8211; so the % of affected assets may be higher, but the chance of actually exploiting those internal apps from an external access point, is much lower.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Understand your attack surface and prioritize patching with CyCognito<\/strong><\/h2>\n\n\n\n<p>CyCognito is not saying that Spring4Shell is trivial or ignorable. But we are saying that this is an example of how exploit intelligence, which ties vulnerability, exploitability and accessibility, is essential for accurate and timely visibility into external risk management.<\/p>\n\n\n\n<p>In many instances critical vulnerabilities may be of lower urgency for your organization than what is reported for the industry. As reported by CISA \u201c<em>&#8230;many vulnerabilities classified as \u201ccritical\u201d are highly complex and have never been seen exploited in the wild &#8211; in fact, only 4% of the total number of CVEs have been publicly exploited.\u201d<\/em><\/p>\n\n\n\n<p>When information is sparse, organizations that are highly risk-averse must treat all threats as top priority. Armed with accurate and comprehensive information on exposure and risk, organizations can focus on what is truly critical for the security of their infrastructure.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>CyCognito allows customers to discover exposure, address security gaps timely, and operate efficiently. To learn more about CyCognito\u2019s approach to attack surface management or if you have questions about this blog, please contact your CyCognito account representative.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NIST assigned Spring4Shell a score of 9.8, most likely out of concern of a similar blast radius to Log4Shell, which was trivial to exploit and very common.<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[88,81],"class_list":["post-220","post","type-post","status-publish","format-standard","hentry","category-research","tag-log4shell","tag-spring4shell"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>One month in: CyCognito looks at Spring4Shell | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"One month in: CyCognito looks at Spring4Shell | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"NIST assigned Spring4Shell a score of 9.8, most likely out of concern of a similar blast radius to Log4Shell, which was trivial to exploit and very common.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-05-05T22:44:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-08T20:54:53+00:00\" \/>\n<meta name=\"author\" content=\"Jason Pappalexis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jason Pappalexis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/\"},\"author\":{\"name\":\"Jason Pappalexis\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d24c88adb69cc9e8748425394054a55b\"},\"headline\":\"One month in: CyCognito looks at Spring4Shell\",\"datePublished\":\"2022-05-05T22:44:00+00:00\",\"dateModified\":\"2024-01-08T20:54:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/\"},\"wordCount\":950,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"keywords\":[\"Log4Shell\",\"Spring4Shell\"],\"articleSection\":[\"Research\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/\",\"name\":\"One month in: CyCognito looks at Spring4Shell | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"datePublished\":\"2022-05-05T22:44:00+00:00\",\"dateModified\":\"2024-01-08T20:54:53+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"One month in: CyCognito looks at Spring4Shell\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d24c88adb69cc9e8748425394054a55b\",\"name\":\"Jason Pappalexis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a3e2da561c68bc740a2a280b72b231ff?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a3e2da561c68bc740a2a280b72b231ff?s=96&d=mm&r=g\",\"caption\":\"Jason Pappalexis\"},\"description\":\"Sr. Technical Marketing Manager\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/jason-pappalexis\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"One month in: CyCognito looks at Spring4Shell | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/","og_locale":"en_US","og_type":"article","og_title":"One month in: CyCognito looks at Spring4Shell | CyCognito Blog","og_description":"NIST assigned Spring4Shell a score of 9.8, most likely out of concern of a similar blast radius to Log4Shell, which was trivial to exploit and very common.","og_url":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/","og_site_name":"CyCognito Blog","article_published_time":"2022-05-05T22:44:00+00:00","article_modified_time":"2024-01-08T20:54:53+00:00","author":"Jason Pappalexis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jason Pappalexis","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/"},"author":{"name":"Jason Pappalexis","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d24c88adb69cc9e8748425394054a55b"},"headline":"One month in: CyCognito looks at Spring4Shell","datePublished":"2022-05-05T22:44:00+00:00","dateModified":"2024-01-08T20:54:53+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/"},"wordCount":950,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"keywords":["Log4Shell","Spring4Shell"],"articleSection":["Research"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/","url":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/","name":"One month in: CyCognito looks at Spring4Shell | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"datePublished":"2022-05-05T22:44:00+00:00","dateModified":"2024-01-08T20:54:53+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/one-month-in-cycognito-looks-at-spring4shell\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"One month in: CyCognito looks at Spring4Shell"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d24c88adb69cc9e8748425394054a55b","name":"Jason Pappalexis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a3e2da561c68bc740a2a280b72b231ff?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3e2da561c68bc740a2a280b72b231ff?s=96&d=mm&r=g","caption":"Jason Pappalexis"},"description":"Sr. Technical Marketing Manager","url":"https:\/\/www.cycognito.com\/blog\/author\/jason-pappalexis\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=220"}],"version-history":[{"count":2,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/220\/revisions"}],"predecessor-version":[{"id":504,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/220\/revisions\/504"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}