n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
No PoCs from references.
- https://github.com/0velychk0/my_bashrc
- https://github.com/4ra1n/4ra1n
- https://github.com/ARPSyndicate/cvemon
- https://github.com/NorthShad0w/FINAL
- https://github.com/OpenNMS/opennms-spring-patched
- https://github.com/Secxt/FINAL
- https://github.com/Tim1995/FINAL
- https://github.com/haba713/depcheck-gretty-issue
- https://github.com/hinat0y/Dataset1
- https://github.com/hinat0y/Dataset10
- https://github.com/hinat0y/Dataset11
- https://github.com/hinat0y/Dataset12
- https://github.com/hinat0y/Dataset2
- https://github.com/hinat0y/Dataset3
- https://github.com/hinat0y/Dataset4
- https://github.com/hinat0y/Dataset5
- https://github.com/hinat0y/Dataset6
- https://github.com/hinat0y/Dataset7
- https://github.com/hinat0y/Dataset8
- https://github.com/hinat0y/Dataset9
- https://github.com/irgoncalves/f5-waf-enforce-sig-Spring4Shell
- https://github.com/muneebaashiq/MBProjects
- https://github.com/nullx3d/PaypScan
- https://github.com/opennms-forge/opennms-spring-patched
- https://github.com/scordero1234/java_sec_demo-main
- https://github.com/seal-community/patches
- https://github.com/sr-monika/sprint-rest
- https://github.com/thomasvincent/Spring4Shell-resources
- https://github.com/thomasvincent/spring-shell-resources
- https://github.com/thomasvincent/springshell
- https://github.com/yycunhua/4ra1n
- https://github.com/zisigui123123s/FINAL