Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
PoC: test-cve-2016-1000027
validation de l'exploitabilité d'une CVE
PoC: CVE-2016-1000027-with-c3p0
An exploit of CVE-2016-1000027 using ysoserial's c3p0 payload type to achieve remote code execution
PoC: spring-web-without-remoting
Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027.
PoC: Spring-Web-5xx-Mitigated-version
Mitigated version for CVE-2016-1000027 spring web.
PoC: cve-2016-1000027-poc
PoC for CVE-2016-1000027
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free