Insecure deserialization In org.springframework:spring-core

Description

Spring Framework allows applications to expose STOMP over WebSocket endpoints Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions

References

1. https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe@%3Cissues.activemq.apache.org%3E2. https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1@%3Cissues.activemq.apache.org%3E3. https://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c@%3Cissues.activemq.apache.org%3E4. https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369@%3Cissues.activemq.apache.org%3E5. https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E6. https://www.exploit-db.com/exploits/44796/7. https://www.oracle.com/security-alerts/cpujul2020.html8. https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html9. https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html10. http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html11. http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html12. http://www.securityfocus.com/bid/10369613. https://www.oracle.com/security-alerts/cpuoct2021.html14. https://github.com/CaledoniaProject/CVE-2018-127015. https://github.com/spring-projects/spring-framework/commit/0009806debb578e884f6dc98bd1f2dc66802002116. https://github.com/spring-projects/spring-framework/commit/e0de9126ed8cf25cf141d3e66420da94e350708a17. https://www.exploit-db.com/exploits/4479618. https://web.archive.org/web/20200227125035/https://www.securityfocus.com/bid/10369619. https://pivotal.io/security/cve-2018-1270