Intel

CVE-2016-1000027

Spring Framework is vulnerable to Remote code execution

Remote code execution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 2, 2020

98

Critical Risk

This Affects:

Spring Framework
Are you affected? Scan for Free

TL;DR

The Spring Framework exposes a class HttpInvokerServiceExporter which is vulnerable to a deserialization attack. The attack can lead to remote code execution. The class was deprecated in version 5.3.0 and removed in version 6.0.0.

Who does this affect?

Aikido has a Java SAST rule that checks for the use of the HttpInvokerServiceExporter class. If you are affected, you will have a critical issue in your feed.

Background info

Spring Framework is vulnerable to Remote code execution in versions < 6.0.0.

How to fix this

Because it is usually not easy to upgrade the framework, we recommend removing all usage of the HttpInvokerServiceExporter class.