Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh46-rmg6-r59w

Опубликовано: 31 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

EPSS

Процентиль: 87%
0.03232
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

EPSS

Процентиль: 87%
0.03232
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502