Spring Statemachine의 Kryo 기반 영속성 백엔드(JPA, MongoDB, Redis 및 ZooKeeper)는 클래스 허용 목록을 적용하지 않고 저장된 상태 머신 컨텍스트를 역직렬화합니다(cwe-502, 신뢰할 수 없는 데이터의 역직렬화). 이는 애플리케이션 JVM 내부에서 원격 코드 실행으로 이어질 수 있습니다. 영향받는 버전: Spring Statemachine 4.0.0부터 4.0.1까지, Spring Statemachine 3.2.0부터 3.2.4까지.
Spring Statemachine의 Kryo 기반 영속성 백엔드(JPA, MongoDB, Redis 및 ZooKeeper)는 클래스 허용 목록을 적용하지 않고 저장된 상태 머신 컨텍스트를 역직렬화합니다(cwe-502, 신뢰할 수 없는 데이터의 역직렬화). 이는 애플리케이션 JVM 내부에서 원격 코드 실행으로 이어질 수 있습니다. 영향받는 버전: Spring Statemachine 4.0.0부터 4.0.1까지, Spring Statemachine 3.2.0부터 3.2.4까지.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4