CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file co...Show more |
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeser...Show more |
2Broadcom Pivotal Software2Spring Batch Spring BatchSep 1, 2026 Jun 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". S...Show more |
2Broadcom Pivotal Software2Spring Batch Spring BatchSep 1, 2026 Jan 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. |