9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Affected (11)
Products: Broadcom: Spring Data Commons · Pivotal Software: Spring Data Rest · Vmware: Spring Data Rest · +2 more
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.12.10 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.0.5 | |
| Up to 2.5.10 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0.8.2.0 |
References (7)
Source: security_alert@emc.com
Mailing ListThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.