CVE-2020-5427
Possibility of SQL Injection in Spring Cloud Data Flow Task Execution Sorting Query
In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Affected products
Spring by VMware · Spring Cloud Data FlowWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →