Multiple Security Flaws Addressed in Core Java Application Subsystems
ID: 3d0272e7-8860-5f03-815d-8ad2b569f7e0
STIX ID: report--3d0272e7-8860-5f03-815d-8ad2b569f7e0
Feed Name: securityonline.info
This advisory details multiple critical vulnerabilities in Spring GraphQL and related integration modules that can enable remote code execution via unsafe deserialization, cross-site WebSocket/session hijacking, arbitrary class loading through crafted Kafka/Pulsar headers, and path traversal in synchronization components. Administrators are strongly advised to apply the listed maintenance updates (e.g., Kafka 4.0.6 / 3.3.16, Pulsar 2.0.6 / 1.2.18, synchronizer 7.0.5) immediately to mitigate exploitation risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
