CVE-2020-5427

HIGH7.2EPSS 1.0%

Possibility of SQL Injection in Spring Cloud Data Flow Task Execution Sorting Query

Published: 3/6/2024Modified: 5/20/2025

Description

In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (2)