Red Hat Bugzilla – Bug 1357929
CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
Last modified: 2016-07-19 11:57:50 EDT
Current installations of Pivotal's Spring Framework suffer from a potential remote code execution (RCE) issue. Depending on how the library is implemented within a product, it may or may not manifest, and authentication may be required. External References: https://www.tenable.com/security/research/tra-2016-20