CVE-2011-2894Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.
CWE-502 · Deserialization of untrusted data
Proof of concept only
A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| GitHub PoC | Exploit PoC for Spring RCE issue (CVE-2011-2894) | 44 | 2013-07-31 |
A defect of the type ARMR addresses, with a fix path to work from and a working exploit already published. This is a claim on attention, not a scheduling commitment: no rule exists and none is scheduled.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification assigned status: MITIGATION-CANDIDATE |
AV:N/AC:M/Au:N/C:P/I:P/A:P
1 metric
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 2.0 | 6.8 | no band published | AV:N/AC:M/Au:N/C:P/I:P/A:P |
NVD | Primary | published |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.springframework:spring-core |
3.0.0 | 3.0.6 |
unbounded |
org.springframework.security:spring-security-core |
3.0.0 | 3.0.6 |
unbounded |
org.springframework.security:spring-security-core |
2.0.0 | 2.0.7 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| osv | org.springframework | spring-core | generic | ≥ 3.0.0 and < 3.0.6 |
| osv | org.springframework.security | spring-security-core | generic | ≥ 2.0.0 and < 2.0.7 · ≥ 3.0.0 and < 3.0.6 |
| nvd | vmware | spring framework | generic | ≥ 3.0.0 and ≤ 3.0.5 |
| nvd | vmware | spring security | generic | ≥ 2.0.0 and ≤ 2.0.6 |
| Published | 2011-10-04 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-16 | NVD's own last-modified date for this record. |