spider-flow API DataSourceController.java DriverManager.getConnection deserialization
CVE-2023-5016
9.8CRITICAL
What is CVE-2023-5016?
A vulnerability exists in Spider-Flow, affecting versions up to 0.5.0, specifically within the DataSourceController.java component. The flaw is associated with the method DriverManager.getConnection, which can be exploited to execute a deserialization attack remotely. This vulnerability could potentially allow unauthorized access and manipulation of sensitive data, posing significant security risks to applications utilizing the affected API.
Affected Version(s)
spider-flow 0.1
spider-flow 0.2
spider-flow 0.3