Issue 179: Spring4Shell zero-day, CRI-O container runtime vulnerability, and REST API security reference
Brief
This week, we have two new vulnerabilities: firstly, the big news in the Spring4Shell zero-day vulnerability in the Spring Framework coming hot on the heels of the recent Log4Shell vulnerability, and secondly, a vulnerability in the CRI-O container runtime that allowed host access to attackers.
We also feature a guide to REST API security and an article on why API security is essential even if you are using an API gateway.
Vulnerability: Spring4Shell zero-day vulnerability in Spring Framework
Hot on the heels of the log4shell vulnerability in December 2021 comes another shell vulnerability — this time the affected component is Java-based Core module in the Spring Framework. The vulnerability has been dubbed Spring4Shell/Springshell, and it allowed unauthenticated attackers to trigger a remote code execution (RCE) on target systems.
