Beveiligingsadvies

CVE-2026-47878

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 05:20:23
Laatst bijgewerkt 2026-08-27 14:32:28
Toegewezen door vmware
CVSS-score 5.6
Status PUBLISHED

Beschrijving

DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.6 and earlier