spring-batch-core is vulnerable to Deserialization of Untrusted Data
56
Medium Risk
spring-batch-core DefaultExecutionContextSerializer passes Base64-decoded bytes to ObjectInputStream.readObject() without an ObjectInputFilter. An attacker who can write execution-context bytes into the JDBC job repository can deserialize untrusted types. MongoDB and ResourcelessJobRepository are not affected. The patch restricts deserialization to a trusted class allow-list.
You are affected if you are using a version that falls within the vulnerable range and the JDBC job repository uses DefaultExecutionContextSerializer.
spring-batch-core is vulnerable to Deserialization of Untrusted Data in versions 0.0.1 - 6.0.4.
Upgrade the org.springframework.batch:spring-batch-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant