spring-integration-jdbc is vulnerable to Deserialization of Untrusted Data
80
High Risk
spring-integration-jdbc JdbcMessageStore drops the configured deserialization allow-list when setBeanClassLoader replaces the converter but the row mapper keeps the old permit-all instance. Operators who called addAllowedPatterns therefore get no protection. An attacker who can write INT_MESSAGE.MESSAGE_CONTENT can still deserialize gadgets. The patch keeps the allow-list on the converter the row mapper actually uses.
You are affected if you are using a version that falls within the vulnerable range and a Spring-managed JdbcMessageStore is used with addAllowedPatterns(...).
spring-integration-jdbc is vulnerable to Deserialization of Untrusted Data in versions 6.4.0 - 7.0.5 and 7.1.0 - 7.1.0.
Upgrade the org.springframework.integration:spring-integration-jdbc library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant