spring-batch-core is vulnerable to Deserialization of Untrusted Data
56
Medium Risk
spring-batch-core JobParameterDeserializer does not enforce the trusted-type allow-list used by Jackson2ExecutionContextStringSerializer. An attacker who can write untrusted job-repository data can instantiate unexpected types, including known Jackson gadget chains. That can lead to code execution during execution-context deserialization. The patch applies the allow-list to job parameter types.
You are affected if you are using a version that falls within the vulnerable range and Jackson2ExecutionContextStringSerializer deserializes job execution context from an untrusted job repository.
spring-batch-core is vulnerable to Deserialization of Untrusted Data in versions 5.2.0 - 6.0.4.
Upgrade the org.springframework.batch:spring-batch-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant