← Back

CVE-2018-1273

Published: Apr 11, 2018Modified: Jun 26, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Affected (11)

Show all products
1 product
Spring Data Commons
Spring Data Rest
1 product
Spring Data Rest
1 product
Ignite
1 product
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Broadcom
Up to 1.12.10
From 1.13.0 to 1.13.10
From 2.0.0 to 2.0.5
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0.0 to 3.0.5
Vmware
Up to 2.5.10
From 2.6.0 to 2.6.10
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.0.1 to 2.5.0
Version 1.0.0
Version 1.0.0 rc3
Configuration D
2 vulnerable

References (7)

Source: security_alert@emc.com
Vendor Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.