CVE-2018-1259
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Affected (5)
Products: Broadcom: Spring Data Commons · Pivotal Software: Spring Data Rest · Vmware: Spring Data Rest · +1 more
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.13 to 1.13.11 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.0.6 | |
| After 2.6 to 2.6.11 |
References (8)
Source: security_alert@emc.com
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.