← Voltar para CVEs
CVE-2020-5413
CRITICAL9.8
Descricao
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution during deserialization. In order to protect against this type of attack, Kryo can be configured to require a set of trusted classes for (de)serialization. Spring Integration should be proactive against blocking unknown "deserialization gadgets" when configuring Kryo in code.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado7/31/2020
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
oracle:banking_corporate_lending_process_managementoracle:banking_credit_facilities_process_managementoracle:banking_supply_chain_financeoracle:banking_virtual_account_managementoracle:flexcube_private_bankingoracle:retail_customer_management_and_segmentation_foundationoracle:retail_merchandising_systemvmware:spring_integration
Fraquezas (CWE)
CWE-502CWE-502
Referencias
https://tanzu.vmware.com/security/cve-2020-5413(security@pivotal.io)
https://www.oracle.com//security-alerts/cpujul2021.html(security@pivotal.io)
https://www.oracle.com/security-alerts/cpuApr2021.html(security@pivotal.io)
https://www.oracle.com/security-alerts/cpuapr2022.html(security@pivotal.io)
https://www.oracle.com/security-alerts/cpuoct2021.html(security@pivotal.io)
https://tanzu.vmware.com/security/cve-2020-5413(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com//security-alerts/cpujul2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuApr2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuapr2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuoct2021.html(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.