PT-2023-30342 · Pivotal · Spring Framework
CVE-2023-47174
·
Publicado
2023-10-31
·
Atualizado
2023-11-08
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Thorn SFTP gateway versions 3.4.x through 3.4.3
Description
The issue arises from the use of Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal. This leads to remote code execution within the context of Thorn SFTP gateway.
Recommendations
For Thorn SFTP gateway versions 3.4.x through 3.4.3, update to version 3.4.4 or later to resolve the issue.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Spring Framework