CVE-2020-5427 MEDIUM

CVE-2020-5427: Possibility of SQL Injection in Spring Cloud Data Flow Task Execution Sorting Query

Vendor Spring By Vmware
Product Spring Cloud Data Flow
Weakness CWE-89 · SQLi
Published January 27, 2021
Last update September 16, 2024

CVSS base score

5.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L

What the vulnerability does

01Description

In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.

Key dates

02Disclosure timeline

January 27, 2021 CVE published
September 16, 2024 Record updated