CVE-2026-47875
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
27/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets.<br />
Spring Batch 6.0.0 - 6.0.4<br />
Spring Batch 5.2.0 - 5.2.6
Impacto
Puntuación base 3.x
5.60
Gravedad 3.x
MEDIA



