GHSA-4wrc-f8pq-fpqp

    Dashboard / Vulnerabilities / GHSA-4wrc-f8pq-fpqp

    GHSA-4wrc-f8pq-fpqp

    Published: 24 May 2022Last Modified: 10 Sept 2026

    Summary: Pivotal Spring Framework contains unsafe Java deserialization methods

    Details: Pivotal Spring Framework before 6.0.0 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. Maintainers recommend investigating alternative components or a potential mitigating control. Version 4.2.6 and 3.2.17 contain [enhanced documentation](https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa) advising users to take precautions against unsafe Java deserialization, version 5.3.0 [deprecate the impacted classes](https://github.com/spring-projects/spring-framework/issues/25379) and version 6.0.0 [removed it entirely](https://github.com/spring-projects/spring-framework/issues/27422).

    Affected packages

    Package

    Name: org.springframework:spring-web

    Purl: pkg:maven/org.springframework/spring-web

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -6.0.0

    Affected versions

    1.0
    1.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High