Spring Security Advisories

CVE-2020-5428: Possibility of SQL Injection in Spring Cloud Task Execution Sorting Query

LOW | JANUARY 25, 2021 | CVE-2020-5428

Description

In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.

Affected Spring Products and Versions

  • Spring Cloud Task
    • 2.2.4 and below

Mitigation

Users should upgrade to 2.2.5 and higher. Releases that have fixed this issue include:

  • Spring Cloud Task
    • 2.3.0
    • 2.2.5

Credit

This issue was identified and responsibly reported by Surfijen Bani of CHECK24 Factory GmbH.

History

  • 2020-11-03: Initial vulnerability identified.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring Runtime offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all