CVE-2016-1000027
CRITICAL9.8EPSS 60.4%Pivotal Spring Framework contains unsafe Java deserialization methods
發布日:2022/5/24修改日:2026/4/28
描述
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
受影響套件(2)
- Debian/libspring-javafrom 0, < 4.2.7-1
- Maven/org.springframework:spring-webfrom 0, < 6.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(17)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-1000027
- PATCHhttps://github.com/spring-projects/spring-framework
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027
- WEBhttps://github.com/spring-projects/spring-framework/commit/2b051b8b321768a4cfef83077db65c6328ffd60f
- WEBhttps://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa
- WEBhttps://github.com/spring-projects/spring-framework/issues/21680
- WEBhttps://github.com/spring-projects/spring-framework/issues/24434
- WEBhttps://github.com/spring-projects/spring-framework/issues/24434#issuecomment-1231625331
- WEBhttps://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626
- WEBhttps://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417
- WEBhttps://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525
- WEBhttps://jira.spring.io/browse/SPR-17143?redirect=false
- WEBhttps://security.netapp.com/advisory/ntap-20230420-0009
- WEBhttps://security-tracker.debian.org/tracker/CVE-2016-1000027
- WEBhttps://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now
- WEBhttps://support.contrastsecurity.com/hc/en-us/articles/4402400830612-Spring-web-Java-Deserialization-CVE-2016-1000027
- WEBhttps://www.tenable.com/security/research/tra-2016-20