Metrics
Affected Vendors & Products
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-47875 |
|
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Batch |
|
| Vendors & Products |
Spring
Spring spring Batch |
Fri, 28 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 27 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 |
Thu, 27 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6 | |
| Title | JobParameterDeserializer bypasses the trusted-type allowlist | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published: 2026-08-27T05:20:21.578Z
Updated: 2026-08-28T16:52:00.046Z
Reserved: 2026-05-20T10:00:58.694Z
Link: CVE-2026-47875
Updated: 2026-08-27T12:38:07.422Z
Status : Awaiting Analysis
Published: 2026-08-27T06:17:17.250
Modified: 2026-08-28T20:17:33.617
Link: CVE-2026-47875
No data.