Loading
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
Use CWE-20, Vmware vendor hub and Spring Boot product page to widen CVE-2017-8046 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44794, CVE-2023-20873 and CVE-2021-26987 for nearby disclosures in the same product family.