In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Spring_framework | Vmware | 5.3.0 (including) | 5.3.49 (excluding) |
| Spring_framework | Vmware | 6.1.0 (including) | 6.1.28 (excluding) |
| Spring_framework | Vmware | 6.2.0 (including) | 6.2.18.1 (excluding) |
| Spring_framework | Vmware | 7.0.0 (including) | 7.0.7.1 (excluding) |
| Libspring-java | Ubuntu | questing | * |