← Back

CVE-2018-1259

nvd nist
Published: May 11, 2018Modified: Jun 26, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Affected (5)

Show all products
1 product
Spring Data Commons
Spring Data Rest
1 product
Spring Data Rest
1 product
Xmlbeam
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Broadcom
From 1.13 to 1.13.11
From 2.0 to 2.0.6
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0 to 3.0.6
After 2.6 to 2.6.11
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.4.14

References (8)

Source: security_alert@emc.com
Third Party Advisory
Source: security_alert@emc.com
Third Party Advisory
Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.