CVE-2023-47174
Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-47174?
CVE-2023-47174 is a vulnerability in Thorn SFTP gateway 3.4.x before 3.4.4 that allows remote code execution through Java deserialization of untrusted data.
What is the severity of CVE-2023-47174?
The severity of CVE-2023-47174 is critical with a CVSS score of 9.8.
How does CVE-2023-47174 affect Thorn SFTP gateway?
CVE-2023-47174 affects Thorn SFTP gateway versions 3.4.x before 3.4.4 and can lead to remote code execution.
How can I fix CVE-2023-47174?
To fix CVE-2023-47174, users should update Thorn SFTP gateway to version 3.4.4 or higher.
Where can I find more information about CVE-2023-47174?
More information about CVE-2023-47174 can be found at the following link: [https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/](https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/)