Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-05T18:01:25.476Z

Reserved: 2023-10-31T00:00:00

Link: CVE-2023-47174

cve-icon Vulnrichment

Updated: 2024-08-02T21:01:22.847Z

cve-icon NVD

Status : Modified

Published: 2023-10-31T04:15:11.313

Modified: 2024-11-21T08:29:54.190

Link: CVE-2023-47174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.