VMware sprung by Spring4shell vulnerability
Other big name vendors investigating.
Source: itnews.com.au
Stay updated with breaking news from Spring Framework. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Other big name vendors investigating.
Security researchers says while Spring4Shell may not be Log4Shell, it’s still a critical vulnerability and security teams need to do the patch and follow the remediation recommendations.
Concern that evolving exploits will hit unpatched applications.
Initial analysis indicates that the bug may not be as severe as Log4Shell
The exploit requires a specific nonstandard configuration to work, limiting the danger it poses, but future research could turn up more broadly usable attacks.