CVE-2020-5411
Published Jun 11, 2020When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blackl…
Vendor/product archive
2 CVEs tagged to pivotal_software / spring_batch — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blackl…
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.