peter bassill · operator
$ cve CVE-2020-5413 JSON

CVE-2020-5413

9.8
CRITICAL · CVSS 3.1 · EPSS 4.4% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution during deserialization. In order to protect against this type of attack, Kryo can be configured to require a set of trusted classes for (de)serialization. Spring Integration should be proactive against blocking unknown "deserialization gadgets" when configuring Kryo in code.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.41% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2020-07-31
Last modified2026-06-17

Affected (8)

VendorProduct
oraclebanking corporate lending process management
oraclebanking credit facilities process management
oraclebanking supply chain finance
oraclebanking virtual account management
oracleflexcube private banking
oracleretail customer management and segmentation foundation
oracleretail merchandising system
vmwarespring integration

References

→ the Explorer  ·  watch your stack  ·  NVD