#VU31796 Deserialization of Untrusted Data in Spring Integration - CVE-2020-5413
Published: July 24, 2020
Spring Integration
Pivotal
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can abuse built-in feature to serialize gadgets to execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.