CVE-2020-29312: Critical severity VMware Spring Framework vulnerability
Published Apr 4, 2023
·Updated
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.
Affected Software
1 affected component
VMware Spring Framework<=3.1.3
Event History
Apr 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-29312?
The severity of CVE-2020-29312 is critical with a severity score of 9.8.
2
What is the description of CVE-2020-29312?
CVE-2020-29312 is a vulnerability found in Zend Framework v.3.1.3 and earlier versions that allows a remote attacker to execute arbitrary code using the unserialize function.
3
How does CVE-2020-29312 affect the Zend Framework?
CVE-2020-29312 affects Zend Framework versions before 3.1.4.
4
Is there a fix available for CVE-2020-29312?
Yes, the fix for CVE-2020-29312 is to upgrade to Zend Framework version 3.1.4 or later.
5
Where can I find more information about CVE-2020-29312?
More information about CVE-2020-29312 can be found in the official website of Zend Framework and the GitHub repository.