ZeroHour

CVE-2020-5427

CVSS 3.1
7.2 high
EPSS
1%p63
Published
()
Modified
Description

In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.

Vendors
vmware
Products
spring cloud data flow
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.