PT-2023-30342 · Pivotal · Spring Framework

CVE-2023-47174

·

Publicado

2023-10-31

·

Atualizado

2023-11-08

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thorn SFTP gateway versions 3.4.x through 3.4.3
Description The issue arises from the use of Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal. This leads to remote code execution within the context of Thorn SFTP gateway.
Recommendations For Thorn SFTP gateway versions 3.4.x through 3.4.3, update to version 3.4.4 or later to resolve the issue.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-47174

Produtos afetados

Spring Framework