CVE-2020-5427

HIGH

Spring Cloud Data Flow <2.6.5-2.5.4 - SQL Injection

Title source: llm
STIX 2.1

Description

In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://tanzu.vmware.com/security/cve-2020-5427

Scores

CVSS v3 7.2
EPSS 0.0105
EPSS Percentile 77.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
vmware/spring_cloud_data_flow 2.5.0 - 2.5.4
Published Jan 27, 2021
Tracked Since Feb 18, 2026