After Spring Cloud, on March 29, another heavyweight vulnerability of Spring broke out on the Internet: Spring Core RCE
The exploit has been uploaded so far exp.py
Patch Links in Spring Production
- JDK version 9 and above
- Spring Framework or derived frameworks are used
At present, Spring has not officially released a patch, it is recommended to reduce the jdk version as a temporary solution