<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>CVE-2022-22965 (Spring4shell) vulnerability evaluation?</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121389948" />
  <subtitle>CVE-2022-22965 (Spring4shell) vulnerability evaluation?</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121389948</id>
  <updated>2026-05-31T17:23:32Z</updated>
  <dc:date>2026-05-31T17:23:32Z</dc:date>
  <entry>
    <title>RE: RE: CVE-2022-22965 (Spring4shell) vulnerability evaluation?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121393378" />
    <author>
      <name>Tobias Liefke</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121393378</id>
    <updated>2022-04-05T17:32:18Z</updated>
    <published>2022-04-05T17:32:17Z</published>
    <summary type="html">&lt;p&gt;Hi David,&lt;/p&gt;
&lt;p&gt;thank you for your response.&lt;/p&gt;
&lt;p&gt;I had the same impression, that the default installation is not
  affected, just wanted to be sure.&lt;/p&gt;
&lt;p&gt;Tobias&lt;/p&gt;</summary>
    <dc:creator>Tobias Liefke</dc:creator>
    <dc:date>2022-04-05T17:32:17Z</dc:date>
  </entry>
  <entry>
    <title>RE: CVE-2022-22965 (Spring4shell) vulnerability evaluation?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121392224" />
    <author>
      <name>David H Nebinger</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121392224</id>
    <updated>2022-04-04T16:27:51Z</updated>
    <published>2022-04-04T16:27:49Z</published>
    <summary type="html">&lt;p&gt;Hi Tobias!&lt;/p&gt;
&lt;p&gt;The official response has been posted to &lt;a
    href="https://help.liferay.com/hc/articles/5202695113357" target="_blank"&gt;https://help.liferay.com/hc/articles/5202695113357&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The TL;DR version: Liferay contains the vulnerable versions, but they
  cannot be exploited in a vanilla Liferay environment, but any
  spring-based customizations (Like SpringPortletMVC, etc) are up to the
  implementors to evaluate.&lt;/p&gt;
&lt;p&gt;New versions of 7.4 will be released with the patched version of
  Spring (I believe for GA19/U19, but it might get pushed to GA20/U20).
  Clients using older versions of Liferay should contact support to get
  an update.&lt;/p&gt;
&lt;p&gt;In case you don't have access to the help.liferay.com article, I'm
  including it below:&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;
    &lt;i&gt;Spring4Shell and Spring Cloud Security Advisory&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Spring Framework &amp;lt;= 5.3.17, &lt;a
    href="https://tanzu.vmware.com/security/cve-2022-22963"
    target="_blank"&gt;CVE-2022-22963&lt;/a&gt;, &lt;a
    href="https://tanzu.vmware.com/security/cve-2022-22965" target="_blank"&gt;CVE-2022-22965&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;Vulnerability Summary&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;On Mar 31, 2022 critical vulnerabilities were published in the Spring
  Framework. Spring is a Java library used by many Java based
  applications worldwide.It is important to note that not all customers
  are affected by this vulnerability. Please read the details below to
  determine whether or not you are impacted by this security issue.&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;What is the concern?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;The primary concern is that the vulnerabilities could be used via a
  simple HTTP request. In some cases the vulnerability is believed to
  provide attackers with the opportunity to execute program code
  remotely. Liferay recommends all customers take immediate steps to
  address the issues.&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;How is Liferay impacted?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Liferay Portal and DXP contain vulnerable versions of Spring Web MVC.
  In the non-customized installation there is no known way to exploit
  the vulnerability, the vulnerable code is not referenced from the
  product.We advise customers with custom portlets or extending Portal
  and DXP functionalities to review and upgrade their Spring libraries.&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;How can I check and mitigate my exposure?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;For code customizations, we recommend to read the VMWare Spring announcements:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;CVE-2022-22963: &lt;a
      href="https://tanzu.vmware.com/security/cve-2022-22963" target="_blank"&gt;https://tanzu.vmware.com/security/cve-2022-22963&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;CVE-2022-22965: &lt;a
      href="https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement" target="_blank"&gt;https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
  &lt;b&gt;Will there be a formal fix for this issue?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;We are working on updating or patching (depending on version) the
  Spring Web MVC library to a safe version, the products do not contain
  Spring Cloud. More updates will be shared on this page.&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;Questions?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Have more questions about the vulnerability? Don’t hesitate to reach
  out to Liferay Support or your Customer Success Manager.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;</summary>
    <dc:creator>David H Nebinger</dc:creator>
    <dc:date>2022-04-04T16:27:49Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2022-22965 (Spring4shell) vulnerability evaluation?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121389947" />
    <author>
      <name>Tobias Liefke</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121389947</id>
    <updated>2022-04-04T07:17:54Z</updated>
    <published>2022-04-04T07:17:22Z</published>
    <summary type="html">&lt;p&gt;As even the latest Liferay CE version 7.4.18 from 2022-04-01 contains
  the vulnerable spring-webmvc.jar in version 5.2.10, I wanted to ask:&lt;/p&gt;
&lt;p&gt;It there an official evaluation available, if and how Liferay is
  affected by CVE-2022-22965?&lt;/p&gt;</summary>
    <dc:creator>Tobias Liefke</dc:creator>
    <dc:date>2022-04-04T07:17:22Z</dc:date>
  </entry>
</feed>
