Miggo Logo

CVE-2020-5413: Code execution in Spring Integration

9.8

CVSS Score
3.1

Basic Information

EPSS Score
0.83622%
Published
8/5/2020
Updated
2/1/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.springframework.integration:spring-integration-coremaven>= 4.3.0, < 4.3.234.3.23
org.springframework.integration:spring-integration-coremaven>= 5.3.0, < 5.3.25.3.2
org.springframework.integration:spring-integration-coremaven>= 5.1.0, < 5.1.125.1.12
org.springframework.integration:spring-integration-coremaven>= 5.2.0, < 5.2.85.2.8

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

Sprin* Int**r*tion *r*m*work provi**s Kryo *o*** impl*m*nt*tions *s *n *lt*rn*tiv* *or J*v* (**)s*ri*liz*tion. W**n Kryo is *on*i*ur** wit* ****ult options, *ll unr**ist*r** *l*ss*s *r* r*solv** on **m*n*. T*is l***s to t** "**s*ri*liz*tion *****ts"

Reasoning

No *n*lysis *v*il**l*