CVE-2020-5413 (CNNVD-202007-1424)
中文标题:
Pivotal Software Spring Integration 代码问题漏洞
英文标题:
Kryo Configuration Allows Code Execution with Unknown "Serialization Gadgets"
漏洞描述
中文描述:
Pivotal Software Spring Integration是美国Pivotal Software公司的的一款企业集成模式。该产品主要用于在基于Spring的应用程序中实现轻量级消息传递,并支持通过声明适配器与尾部系统集成。 Pivotal Software Spring Integration中存在代码问题漏洞。攻击者可利用该漏洞执行任意代码。以下产品及版本受到影响:Pivotal Software Spring Integration 4.3.0版本至4.3.22版本,5.1.0版本至5.1.11版本,5.2.0版本至5.2.7版本,5.3.0版本至5.3.1版本。
英文描述:
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution during deserialization. In order to protect against this type of attack, Kryo can be configured to require a set of trusted classes for (de)serialization. Spring Integration should be proactive against blocking unknown "deserialization gadgets" when configuring Kryo in code.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Spring by VMware | Spring Integration | - | < v4.3.23.RELEASE | - |
cpe:2.3:a:spring_by_vmware:spring_integration:*:*:*:*:*:*:*:*
|
| vmware | spring_integration | * | - | - |
cpe:2.3:a:vmware:spring_integration:*:*:*:*:*:*:*:*
|
| oracle | banking_corporate_lending_process_management | 14.2.0 | - | - |
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2.0:*:*:*:*:*:*:*
|
| oracle | banking_corporate_lending_process_management | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_corporate_lending_process_management | 14.5.0 | - | - |
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0:*:*:*:*:*:*:*
|
| oracle | banking_credit_facilities_process_management | 14.2.0 | - | - |
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2.0:*:*:*:*:*:*:*
|
| oracle | banking_credit_facilities_process_management | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_credit_facilities_process_management | 14.5.0 | - | - |
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5.0:*:*:*:*:*:*:*
|
| oracle | banking_supply_chain_finance | 14.2.0 | - | - |
cpe:2.3:a:oracle:banking_supply_chain_finance:14.2.0:*:*:*:*:*:*:*
|
| oracle | banking_supply_chain_finance | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_supply_chain_finance:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_supply_chain_finance | 14.5.0 | - | - |
cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0:*:*:*:*:*:*:*
|
| oracle | banking_virtual_account_management | 14.2.0 | - | - |
cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:*:*:*:*:*:*:*
|
| oracle | banking_virtual_account_management | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_virtual_account_management | 14.5.0 | - | - |
cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:*:*:*:*:*:*:*
|
| oracle | flexcube_private_banking | 12.0.0 | - | - |
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
|
| oracle | flexcube_private_banking | 12.1.0 | - | - |
cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
|
| oracle | retail_customer_management_and_segmentation_foundation | * | - | - |
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:*:*:*:*:*:*:*:*
|
| oracle | retail_merchandising_system | 16.0.3 | - | - |
cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-5413 |
2025-11-11 15:20:39 | 2025-11-11 07:36:24 |
| NVD | nvd_CVE-2020-5413 |
2025-11-11 14:57:01 | 2025-11-11 07:44:47 |
| CNNVD | cnnvd_CNNVD-202007-1424 |
2025-11-11 15:10:28 | 2025-11-11 07:56:22 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202007-1424
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 4 -> 18
- data_sources: ['cve'] -> ['cve', 'nvd']