← Back to feed
Vulnerabilities & PatchesEmerging1 sourceApr 6, 2022 · 18:00via API Security News

Issue 179: Spring4Shell zero-day, CRI-O container runtime vulnerability, and REST API security reference

Brief

This week, we have two new vulnerabilities: firstly, the big news in the Spring4Shell zero-day vulnerability in the Spring Framework coming hot on the heels of the recent Log4Shell vulnerability, and secondly, a vulnerability in the CRI-O container runtime that allowed host access to attackers.

We also feature a guide to REST API security and an article on why API security is essential even if you are using an API gateway.

Vulnerability: Spring4Shell zero-day vulnerability in Spring Framework

Hot on the heels of the log4shell vulnerability in December 2021 comes another shell vulnerability — this time the affected component is Java-based Core module in the Spring Framework. The vulnerability has been dubbed Spring4Shell/Springshell, and it allowed unauthenticated attackers to trigger a remote code execution (RCE) on target systems.

Read more on API Security News