Skip to main content

Vendor/product archive

pivotal_software / spring_batch CVEs

Beta · best-effort

2 CVEs tagged to pivotal_software / spring_batch1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-5411

Published Jun 11, 2020

When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blackl…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3774

Published Jan 18, 2019

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1