Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
PoC: spring-break_cve-2017-8046
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
PoC: SpringBreakVulnerableApp
WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!
PoC: cve-2017-8046
cve-2017-8046
PoC: spring-break-cve-2017-8046
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
PoC: SpringBreakPoC
PoC for SpringBreak (CVE-2017-8046)
PoC: spring-data-rest-CVE-2017-8046
Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)
PoC: CVE-2017-8046-DEMO
SPRING DATA REST CVE-2017-8046 DEMO
PoC: CVE-2017-8046-DEMO
SPRING DATA REST CVE-2017-8046 DEMO
PoC: CVE-2017-8046
修改IP地址即可实现命令执行
PoC: VulnerableSpringDataRest
An intentionally vulnerable (CVE-2017-8046) SrpingData REST appl with Swagger Support for pentesting purposes
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free