{"id":46035,"date":"2022-04-05T01:11:24","date_gmt":"2022-04-05T01:11:24","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=110715"},"modified":"2022-04-05T01:11:24","modified_gmt":"2022-04-05T01:11:24","slug":"springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/","title":{"rendered":"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965"},"content":{"rendered":"<p>On March 31, 2022, vulnerabilities in the Spring Framework for Java were <a href=\"https:\/\/www.springcloud.io\/post\/2022-03\/spring-framework-rce-early-announcement\/#gsc.tab=0\" target=\"_blank\" rel=\"noreferrer noopener\">publicly disclosed<\/a>. Microsoft is currently assessing the impact associated with these vulnerabilities. This blog is for customers looking for protection against exploitation and ways to detect vulnerable installations on their network of the critical remote code execution (RCE) vulnerability <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-22965\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-22965<\/a> (also known as SpringShell or Spring4Shell).<\/p>\n<p>The Spring Framework is the most widely used lightweight open-source framework for Java. In Java Development Kit (JDK) version 9.0 or later, a remote attacker can obtain an <em>AccessLogValve <\/em>object through the framework\u2019s parameter binding feature and use malicious field values to trigger the pipeline mechanism and write to a file in an arbitrary path, if certain conditions are met.&nbsp;<\/p>\n<p>The vulnerability in Spring Core\u2014referred to in the security community as SpringShell or Spring4Shell\u2014can be exploited when an attacker sends a specially crafted query to a web server running the Spring Core framework.&nbsp;Other vulnerabilities disclosed in the same component are less critical and not tracked as part of this blog.<\/p>\n<p>Impacted systems have the following traits:<\/p>\n<ul>\n<li>Running JDK 9.0 or later<\/li>\n<li>Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and earlier versions<\/li>\n<li>Apache Tomcat as the Servlet container<\/li>\n<li>Packaged as a traditional Java web archive (WAR) and deployed in a standalone Tomcat instance; typical Spring Boot deployments using an embedded Servlet container or reactive web server are not impacted<\/li>\n<li>Tomcat has <em>spring-webmvc<\/em> or <em>spring-webflux<\/em> dependencies<\/li>\n<\/ul>\n<p>Any system using JDK 9.0 or later and using the Spring Framework or derivative frameworks should be considered vulnerable. The following nonmalicious command can be used to determine vulnerable systems:<\/p>\n<pre class=\"wp-block-preformatted\">$ curl host:port\/path?class.module.classLoader.URLs%5B0%5D=0<\/pre>\n<p>A host that returns an HTTP 400 response should be considered vulnerable to the attack detailed in the proof of concept (POC) below. Note that while this test is a good indicator of a system\u2019s susceptibility to an attack, any system within the scope of impacted systems listed above should still be considered vulnerable.<\/p>\n<p>The <a href=\"https:\/\/docs.microsoft.com\/azure\/defender-for-cloud\/deploy-vulnerability-assessment-tvm\" target=\"_blank\" rel=\"noreferrer noopener\">threat and vulnerability management<\/a> console within <a href=\"https:\/\/www.microsoft.com\/microsoft-365\/security\/microsoft-365-defender\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft 365 Defender<\/a> provides detection and reporting for this vulnerability.<\/p>\n<h2>Observed activity<\/h2>\n<p>Microsoft regularly monitors attacks against our cloud infrastructure and services to defend them better. Since the Spring Core vulnerability was announced, we have been tracking a low volume of exploit attempts across our cloud services for Spring Cloud and Spring Core vulnerabilities.&nbsp;For CVE-2022-22965, the attempts closely align with the basic web shell POC described in this post.<\/p>\n<h2>Attack breakdown<\/h2>\n<p>CVE-2022-22965 affects functions that use request mapping annotation and Plain Old Java Object (POJO) parameters within the Spring Framework. The POC code creates a controller that, when loaded into Tomcat, handles HTTP requests. <\/p>\n<p>The only publicly available working POC is specific to Tomcat server\u2019s logging properties via the <em>ClassLoader<\/em> module in the <em>propertyDescriptor<\/em> cache.&nbsp;The attacker can update the <em>AccessLogValve<\/em> class using the module to create a web shell in the Tomcat root directory called <em>shell.jsp<\/em>. The attacker can then change the default access logs to a file of their choosing.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"801\" height=\"436\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig1-poc-screenshot.png\" alt=\"Screenshot of an application UI with lines of code. One of said code lines is highlighted, with an annotation written in a non-English language.\" class=\"wp-image-110718\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig1-poc-screenshot.png 801w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig1-poc-screenshot-300x163.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig1-poc-screenshot-768x418.png 768w\" sizes=\"auto, (max-width: 801px) 100vw, 801px\"><figcaption>Figure 1. Screenshot from the original POC code post<\/figcaption><\/figure>\n<p>The changes to <em>AccessValveLog<\/em> can be achieved by an attacker who can use HTTP requests to create a <em>.jsp<\/em> file in the service\u2019s root directory. In the example below, each GET parameter is set as a Java object property. Each GET request then executes a Java code resembling the example below, wherein the final segment \u201csetPattern\u201d would be unique for each call (such as setPattern, setSuffix, setDirectory, and others):&nbsp;<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"797\" height=\"54\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet1.png\" alt=\"Screenshot of Java codes of an actual exploit.\" class=\"wp-image-110721\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet1.png 797w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet1-300x20.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet1-768x52.png 768w\" sizes=\"auto, (max-width: 797px) 100vw, 797px\"><\/figure>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"799\" height=\"106\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig2-poc-screenshot.png\" alt=\"Screenshot of several lines of HTTP URLs.\" class=\"wp-image-110724\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig2-poc-screenshot.png 799w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig2-poc-screenshot-300x40.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig2-poc-screenshot-768x102.png 768w\" sizes=\"auto, (max-width: 799px) 100vw, 799px\"><figcaption>Figure 2. Screenshot from the original POC code post<\/figcaption><\/figure>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"800\" height=\"840\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig3-poc-screenshot.png\" alt=\"Screenshot of an application UI with lines of code.\" class=\"wp-image-110730\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig3-poc-screenshot.png 800w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig3-poc-screenshot-286x300.png 286w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig3-poc-screenshot-768x806.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\"><figcaption>Figure 3. Screenshot from the original POC code post<\/figcaption><\/figure>\n<p>The <em>.jsp<\/em> file now contains a payload with a password-protected web shell with the following format:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"797\" height=\"120\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet3.png\" alt=\"Screenshot of the payload's web shell code.\" class=\"wp-image-110733\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet3.png 797w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet3-300x45.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/springshell-code-snippet3-768x116.png 768w\" sizes=\"auto, (max-width: 797px) 100vw, 797px\"><\/figure>\n<p>The attacker can then use HTTP requests to execute commands. While the above POC depicts a command shell as the inserted code, this attack could be performed using any executable code.<\/p>\n<h2>The vulnerability and exploit in depth<\/h2>\n<p>The vulnerability in Spring results in a client\u2019s ability, in some cases, to modify sensitive internal variables inside the web server or application by carefully crafting the HTTP request.<\/p>\n<p>In the case of the Tomcat web server, the vulnerability allowed for that manipulation of the Access Log to be placed in an arbitrary path with somewhat arbitrary contents. The POC above sets the contents to be a JSP web shell and the path inside the Tomcat\u2019s web application ROOT directory, which essentially drops a reverse shell inside Tomcat. For the web application to be vulnerable, it needs to use Spring\u2019s request mapping feature, with the handler function receiving a Java object as a parameter.<\/p>\n<h3>Background<\/h3>\n<h4>Request mapping and request parameter binding<\/h4>\n<p>Spring allows developers to map HTTP requests to Java handler methods. The web application\u2019s developer can ask Spring to call an appropriate handler method each time a user requests a specific URI. For instance, the following web application code will cause Spring to invoke the method <em>handleWeatherRequest<\/em> each time a user requests the URI <em>\/WeatherReport<\/em>:<\/p>\n<pre class=\"wp-block-preformatted\"><code>@RequestMapping(\u201c\/WeatherReport\u201d)<\/code>\npublic string handleWeatherRequest(Location reportLocation)\n{\n\u2026\n}<\/pre>\n<p>Moreover, through request parameter binding, the handler method can accept arguments passed through parameters in GET\/POST\/REST requests. In the above example, Spring will instantiate a <em>Location<\/em> object, initialize its fields according to the HTTP request\u2019s parameters, and pass it on to <em>handleWeatherRequest<\/em>. So, if, for instance, <em>Location<\/em> will be defined as:<\/p>\n<pre class=\"wp-block-preformatted\"><code>class Location<br>{<br>&nbsp;&nbsp;&nbsp; public void setCountry(string country) {\u2026}<br>&nbsp;&nbsp;&nbsp; public void setCity(string city) {\u2026}<br>&nbsp;&nbsp;&nbsp; public string getCountry() {\u2026}<br>&nbsp;&nbsp;&nbsp; public string getCity() {\u2026}<br>}<\/code><\/pre>\n<p>If we issue the following HTTP request:<\/p>\n<pre class=\"wp-block-preformatted\"><code>example.com\/WeatherReport?country=USA&amp;city=Redmond<\/code><\/pre>\n<p>The resulting call to <em>handleWeatherRequest<\/em> will automatically have a <em>reportLocation<\/em> argument with the country set to USA and city set to Redmond. <\/p>\n<p>If <em>Location<\/em> had a sub-object named <em>coordinates<\/em>, which contained <em>longitude<\/em> and <em>latitude<\/em> parameters, then Spring would try and initialize them out of the parameters of an incoming request. For example, when receiving a request with GET params <em>coordinates.longitude=123&amp;coordinate.latitude=456<\/em> Spring would try and set those values in the <em>coordinates<\/em> member of <em>location<\/em>, before handing over control to <em>handleWeatherRequest<\/em>.<\/p>\n<p>The SpringShell vulnerability directly relates to the process Spring uses to populate these fields.<\/p>\n<h4>The process of property binding<\/h4>\n<p>Whenever Spring receives an HTTP request mapped to a handler method as described above, it will try and bind the request\u2019s parameters for each argument in the handler method. Now, to stick with the previous example, a client asked for:<\/p>\n<pre class=\"wp-block-preformatted\"><code>example.com\/WeatherReport?x.y.z=foo<\/code><\/pre>\n<p>Spring would instantiate the argument (in our case, create a <em>Location<\/em> object). Then it breaks up the parameter name by dots (.) and tries to do a series of steps:<\/p>\n<ol type=\"1\">\n<li>Use Java introspection to map all accessors and mutators in <em>location<\/em><\/li>\n<li>If location has a getX<em>()<\/em> accessor, call it to get the <em>x<\/em> member of location<\/li>\n<li>Use Java introspection to map all accessors and mutators in the<em> x<\/em> object<\/li>\n<li>If the <em>x<\/em> object has a <em>getY<\/em>() accessor, call it to get the <em>y<\/em> object inside of the <em>x<\/em> object<\/li>\n<li>Use Java introspection to map all accessors and mutators in the<em> y<\/em> object<\/li>\n<li>If the <em>y<\/em> object has a <em>setZ()<\/em> mutator, call it with parameter <em>\u201cfoo\u201d<\/em><\/li>\n<\/ol>\n<p>So essentially, ignoring the details, we get <em>location.getX().getY().setZ(\u201cfoo\u201d)<\/em>.<\/p>\n<h3>The vulnerability and its exploitation<\/h3>\n<h4>Prelude: CVE-2010-1622<\/h4>\n<p>In June 2010, a CVE was <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2010-1622\" target=\"_blank\" rel=\"noreferrer noopener\">published<\/a> for the Spring framework. The crux of the CVE was as follows:<\/p>\n<ol type=\"1\">\n<li>All Java objects implicitly contain a <em>getClass()<\/em> accessor that returns the <em>Class<\/em> describing the object\u2019s class.<\/li>\n<li><em>Class<\/em> objects have a <em>getClassLoader()<\/em> accessor the gets the <em>ClassLoader<\/em> object.<\/li>\n<li>Tomcat uses its own class loader for its web applications. This class loader contains various members that can affect Tomcat\u2019s behavior. One such member is <em>URLs<\/em>, which is an array of URLs the class loader uses to retrieve resources.<\/li>\n<li>Overwriting one of the URLs with a URL to a remote JAR file would cause Tomcat to subsequently load the JAR from an attacker-controlled location.<\/li>\n<\/ol>\n<p>The bug was fixed in Spring by preventing the mapping of the <em>getClassLoader()<\/em> or <em>getProtectionDomain()<\/em> accessors of <em>Class<\/em> objects during the property-binding phase. Hence <em>class.classLoader<\/em> would not resolve, thwarting the attack.<\/p>\n<h4>The current exploit: CVE-2022-22965<\/h4>\n<p>The current exploit leverages the same mechanism as in CVE-2010-1622, bypassing the previous bug fix. Java 9 added a new technology called Java Modules. An accessor was added to the <em>Class<\/em> object, called <em>getModule()<\/em>. The <em>Module<\/em> object contains a <em>getClassLoader()<\/em> accessor. Since the CVE-2010-1622 fix only prevented mapping the <em>getClassLoader()<\/em> accessor of <em>Class<\/em> objects, Spring mapped the <em>getClassLoader()<\/em> accessor of the <em>Module<\/em> object. Once again, one could reference the class loader from Spring via the <em>class.module.classLoader<\/em> parameter name prefix.<\/p>\n<h3>From ClassLoader to AccessLogValve<\/h3>\n<p>The latest exploit uses the same accessor chaining, via the Tomcat class loader, to drop a JSP web shell on the server.<\/p>\n<p>This is done by manipulating the properties of the <em>AccessLogValve<\/em> object in Tomcat\u2019s pipeline. The <em>AccessLogValve <\/em>is referenced using the <em>class.module.classLoader.resources.context.parent.pipeline.first<\/em> parameter prefix.<\/p>\n<p>The following properties are changed:<\/p>\n<ol type=\"1\">\n<li><strong>Directory: <\/strong>The path where to store the access log, relative to Tomcat\u2019s root directory. This can be manipulated to point into a location accessible by http requests, such as the web application\u2019s directory.<\/li>\n<li><strong>Prefix: <\/strong>The prefix of the access log file name<\/li>\n<li><strong>Suffix: <\/strong>The suffix of the access log file name. The log file name is a concatenation of the prefix with the suffix.<\/li>\n<li><strong>Pattern: <\/strong>A string that describes the log record structure. This can be manipulated so that each record will essentially contain a JSP web shell.<\/li>\n<li><strong>FileDateFormat:<\/strong> Setting this causes the new access log settings to take effect.<\/li>\n<\/ol>\n<p>Once the web shell is dropped on the server, the attacker can execute commands on the server as Tomcat.<\/p>\n<h2>Discovery and mitigations<\/h2>\n<h3>How to find vulnerable devices<\/h3>\n<p id=\"workarounds\"><a href=\"https:\/\/www.microsoft.com\/security\/business\/threat-protection\/threat-vulnerability-management\" target=\"_blank\" rel=\"noreferrer noopener\">Threat and vulnerability management<\/a> capabilities in <a href=\"https:\/\/www.microsoft.com\/security\/business\/threat-protection\/endpoint-defender\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Defender for Endpoint<\/a> monitor an organization\u2019s overall security posture and equip customers with real-time insights into organizational risk through continuous vulnerability discovery, intelligent prioritization, and the ability to seamlessly remediate vulnerabilities. <\/p>\n<p id=\"workarounds\">Customers can now search for CVE-2022-22965 to find vulnerable devices through the <a href=\"https:\/\/securitycenter.microsoft.com\/vulnerabilities?search=CVE-2022-22965\" target=\"_blank\" rel=\"noreferrer noopener\">Weaknesses<\/a> page in threat and vulnerability management.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"975\" height=\"220\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/image.png\" alt=\"Screenshot of the Weaknesses page where one can search for CVE-2022-22965 to find vulnerable devices.\" class=\"wp-image-110844\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/image.png 975w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/image-300x68.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/image-768x173.png 768w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\"><figcaption>Figure 4. Weaknesses page in Microsoft Defender for Endpoint<\/figcaption><\/figure>\n<h3>Enhanced protection with&nbsp;Azure Firewall Premium<\/h3>\n<p>Customers using <a href=\"https:\/\/docs.microsoft.com\/azure\/firewall\/premium-migrate\" target=\"_blank\" rel=\"noreferrer noopener\">Azure Firewall Premium<\/a> have enhanced protection from the SpringShell CVE-2022-22965 vulnerability and exploits. Azure Firewall Premium Intrusion Detection and Prevention System (IDPS) provides IDPS inspection for all east-west traffic, outbound traffic to the internet, and inbound HTTP traffic from the internet. The vulnerability rulesets are continuously updated and include vulnerability protection for SpringShell since March 31, 2022. The screenshot below shows all the scenarios which are actively mitigated by Azure Firewall Premium.<\/p>\n<p>Configure Azure Firewall Premium with both IDPS Alert &amp; Deny mode and TLS inspection enabled for proactive protection against CVE-2022-22965 exploit.\u202f\u202f<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"798\" height=\"120\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig5-azure-firewall-premium-portal-624bcc63b0e39.png\" alt=\"Screenshot of the Azure Firewall Premium portal UI displaying alerts related to CVE-2022-22965 exploit attempts.\" class=\"wp-image-111012\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig5-azure-firewall-premium-portal-624bcc63b0e39.png 798w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig5-azure-firewall-premium-portal-624bcc63b0e39-300x45.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig5-azure-firewall-premium-portal-624bcc63b0e39-768x115.png 768w\" sizes=\"auto, (max-width: 798px) 100vw, 798px\"><figcaption>Figure 5. Azure Firewall Premium portal detecting CVE-2022-22965 exploitation attempts.<\/figcaption><\/figure>\n<p>Customers using Azure Firewall Standard can migrate to Premium by following <a href=\"https:\/\/docs.microsoft.com\/azure\/firewall\/premium-migrate\" target=\"_blank\" rel=\"noreferrer noopener\">these directions<\/a>. Customers new to Azure Firewall Premium can learn more about <a href=\"https:\/\/docs.microsoft.com\/azure\/firewall\/premium-features\" target=\"_blank\" rel=\"noreferrer noopener\">Firewall Premium<\/a>.<\/p>\n<h3>Patch information and workarounds<\/h3>\n<p>Customers are encouraged to apply these mitigations to reduce the impact of this threat. Check the recommendations card in Microsoft 365 Defender threat and vulnerability management for the deployment status of monitored mitigations.<\/p>\n<ul>\n<li>An <a href=\"https:\/\/spring.io\/blog\/2022\/03\/31\/spring-boot-2-6-6-available-now\" target=\"_blank\" rel=\"noreferrer noopener\">update<\/a> is available for CVE-2022-22965. Administrators should upgrade to versions 5.3.18 or later or 5.2.19 or later. If the patch is applied, no other mitigation is necessary.<\/li>\n<\/ul>\n<p>If you\u2019re unable to patch CVE-2022-22965, you can implement this set of workarounds published by <a href=\"https:\/\/www.springcloud.io\/post\/2022-03\/spring-framework-rce-early-announcement\/#gsc.tab=0\" target=\"_blank\" rel=\"noreferrer noopener\">Spring<\/a>:<\/p>\n<ul>\n<li>Search the @InitBinder annotation globally in the application to see if the dataBinder.setDisallowedFields method is called in the method body. If the introduction of this code snippet is found, add <code>{\"class.*\",\"Class.*\",\"*.class.*\", \"*.Class.*\"}<\/code> to the original blacklist. (<strong>Note:<\/strong> If this code snippet is used a lot, it needs to be appended in each location.)<\/li>\n<li>Add the following global class into the package where the Controller is located. Then recompile and test the project for functionality:<\/li>\n<\/ul>\n<pre class=\"wp-block-preformatted\">import org.springframework.core.annotation.Order; import org.springframework.web.bind.WebDataBinder; import org.springframework.web.bind.annotation.ControllerAdvice; import org.springframework.web.bind.annotation.InitBinder; @ControllerAdvice @Order(10000) public class GlobalControllerAdvice{ @InitBinder public void setAllowedFields(webdataBinder dataBinder){ String[]abd=new string[]{\"class.*\",\"Class.*\",\"*.class.*\",\"*.Class.*\"}; dataBinder.setDisallowedFields(abd); } }<\/pre>\n<h2>Detections<\/h2>\n<h3>Microsoft 365 Defender<\/h3>\n<h4>Endpoint detection and response (EDR)<\/h4>\n<p>Alerts with the following title in the security center can indicate threat activity on your network:<\/p>\n<ul>\n<li>Possible SpringShell exploitation<\/li>\n<\/ul>\n<p>The following alerts for an observed attack, but might not be unique to exploitation for this vulnerability:<\/p>\n<ul>\n<li>Suspicious process executed by a network service<\/li>\n<\/ul>\n<h4>Antivirus<\/h4>\n<p>Microsoft Defender antivirus version <strong>1.361.1234.0<\/strong> or later detects components and behaviors related to this threat with the following detections:<\/p>\n<ul>\n<li>Trojan:Python\/SpringShellExpl<\/li>\n<li>Exploit:Python\/SpringShell<\/li>\n<li>Backdoor:PHP\/Remoteshell.V<\/li>\n<\/ul>\n<h3>Hunting<\/h3>\n<h4>Microsoft 365 Defender advanced hunting queries&nbsp;<\/h4>\n<p>Use the query below to surface exploitation of CVE-2022-22965 on both victim devices and devices performing the exploitation. Note that this query only covers HTTP use of the exploitation and not HTTPS.<\/p>\n<pre class=\"wp-block-preformatted\">DeviceNetworkEvents\n| where Timestamp &gt; ago(7d)\n| where ActionType =~ \"NetworkSignatureInspected\"\n| where AdditionalFields contains \".jsp?cmd=\"\n| summarize makeset(AdditionalFields, 5), min(Timestamp), max(Timestamp) by DeviceId, DeviceName <\/pre>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/04\/04\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft provides guidance for customers looking for protection against exploitation and ways to detect vulnerable installations on their network of the critical vulnerability CVE-2022-22965, also known as SpringShell or Spring4Shell.<br \/>\nThe post SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":46036,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347,7221,9942,9943,19],"class_list":["post-46035","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity","tag-microsoft-security-intelligence","tag-spring-framework","tag-springshell","tag-vulnerabilities"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-05T01:11:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig1-poc-screenshot.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965\",\"datePublished\":\"2022-04-05T01:11:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/\"},\"wordCount\":2072,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png\",\"keywords\":[\"Cybersecurity\",\"Microsoft security intelligence\",\"Spring Framework\",\"SpringShell\",\"Vulnerabilities\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/\",\"name\":\"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png\",\"datePublished\":\"2022-04-05T01:11:24+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png\",\"width\":801,\"height\":436},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/","og_locale":"en_US","og_type":"article","og_title":"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-04-05T01:11:24+00:00","og_image":[{"url":"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/04\/fig1-poc-screenshot.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965","datePublished":"2022-04-05T01:11:24+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/"},"wordCount":2072,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png","keywords":["Cybersecurity","Microsoft security intelligence","Spring Framework","SpringShell","Vulnerabilities"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/","url":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/","name":"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png","datePublished":"2022-04-05T01:11:24+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/04\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965.png","width":801,"height":436},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46035","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=46035"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46035\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/46036"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=46035"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=46035"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=46035"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}