jenkins-2.462
Chainguard
9.8
CVSS V3
Status
Justification
Impact
This CVE is disputed by upstream Spring Framework developers: https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417. The Spring Framework provides an option to invoke ObjectInputStream (along with documented warnings). The presence of this capability in the Spring Framework does not represent a vulnerability.
Status