Web Hack List

Other nomination

Remote Code Execution with Spring Properties

A restricted upload that can only write allow-listed extensions into a Spring Boot application's working directory becomes remote code execution by dropping a configuration file there: Spring loads it, an attacker-set logging property makes the logging framework fetch a remote configuration, and its JNDI element triggers a lookup that executes code on restart.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.