CyberRota Analysis
AI-GeneratedThe vulnerability affects Spring Integration versions 6.4.0 through 7.1.0, where improper handling of deserialization in JdbcMessageStore can lead to unauthorized access or manipulation of data. Operators using the addAllowedPatterns(...) method to restrict deserialization are left unprotected when the store is managed by Spring, potentially allowing attackers to exploit this weakness. Organizations utilizing affected Spring Integration versions should prioritize patching to mitigate the risk of data breaches and unauthorized actions.
Original NVD Description
An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Related CVEs
Other vulnerabilities affecting the same vendor(s)