First published: Thu Jan 04 2018(Updated: )
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Spring Boot | <1.5.9 | |
Vmware Spring Boot | =2.0.0-milestone1 | |
Vmware Spring Boot | =2.0.0-milestone2 | |
Vmware Spring Boot | =2.0.0-milestone3 | |
Vmware Spring Boot | =2.0.0-milestone4 | |
Vmware Spring Boot | =2.0.0-milestone5 | |
Pivotal Software Spring Data Rest | <2.6.9 | |
Pivotal Software Spring Data Rest | =3.0.0 | |
Pivotal Software Spring Data Rest | =3.0.0-m1 | |
Pivotal Software Spring Data Rest | =3.0.0-m2 | |
Pivotal Software Spring Data Rest | =3.0.0-m3 | |
Pivotal Software Spring Data Rest | =3.0.0-m4 | |
Pivotal Software Spring Data Rest | =3.0.0-rc1 | |
Pivotal Software Spring Data Rest | =3.0.0-rc2 | |
Pivotal Software Spring Data Rest | =3.0.0-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8046 is a vulnerability that allows malicious PATCH requests to run arbitrary Java code on servers using Spring Data REST versions prior to 2.6.9, versions prior to 3.0.1, and Spring Boot versions prior to 1.5.9, 2.0 M6.
CVE-2017-8046 has a severity rating of 9.8 (Critical).
CVE-2017-8046 affects servers using Spring Data REST versions prior to 2.6.9, versions prior to 3.0.1, and Spring Boot versions prior to 1.5.9, 2.0 M6.
To mitigate CVE-2017-8046, upgrade Spring Data REST to version 2.6.9 or newer, version 3.0.1 or newer, and upgrade Spring Boot to version 1.5.9 or newer, 2.0 M6 or newer.
You can find more information about CVE-2017-8046 at the following references: [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2018:2405), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1553024), [SecurityFocus](http://www.securityfocus.com/bid/100948).