Back to Database
Status published
Medium
CVE-2020-5428
Possibility of SQL Injection in Spring Cloud Task Execution Sorting Query
Vulnerability Description
In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5428
Credits & Attribution
No credits recorded in the NVD database.
More from Spring by VMware
View All →CVE-2020-5427
Possibility of SQL Injection in Spring Cloud Data Flow Task Execution Sorting Query
Medium
5.7
CVE-2020-5421
RFD Protection Bypass via jsessionid
High
8.7
CVE-2020-5413
Kryo Configuration Allows Code Execution with Unknown "Serialization Gadgets"
Critical
9.8
CVE-2020-5412
Hystrix Dashboard Proxy In spring-cloud-netflix-hystrix-dashboard
Medium
6.5
CVE-2020-5411
Jackson Configuration Allows Code Execution with Unknown "Serialization Gadgets"
High
8.1
Affected Vendor
Spring by VMware
View all reports →Affected Software
Spring Cloud Task
Vulnerable Versions:
2.2
Timeline
Official Publish:
January 27th, 2021
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L