CVE-2018-1259: XEE

Published May 11, 2018
·
Updated

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Affected Software

10 affected componentsFixes available
Pivotal Software Spring Data Commons>=1.13<=1.13.11
Pivotal Software Spring Data Commons>=2.0<=2.0.6
Pivotal Software Spring Data Rest>2.6<=2.6.11
Pivotal Software Spring Data Rest>=3.0<=3.0.6
XMLBeam XMLBeam<=1.4.14
redhat/spring-data-commons<1.13.12
1.13.12
redhat/spring-data-commons<2.0.7
2.0.7
Broadcom Spring Data Commons>=1.13<=1.13.11
Broadcom Spring Data Commons>=2.0<=2.0.6
VMware Spring Data REST>2.6<=2.6.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/spring-data-commons to a version that resolves this vulnerability.

    Fixed in 1.13.12
  2. Upgrade

    Upgrade redhat/spring-data-commons to a version that resolves this vulnerability.

    Fixed in 2.0.7
  3. Upgrade

    Upgrade Spring Data Commons to a version that resolves this vulnerability.

    Fixed in 1.13.12
  4. Upgrade

    Upgrade Spring Data Commons to a version that resolves this vulnerability.

    Fixed in 2.0.7
  5. Compensating control

    If upgrading is not immediately possible, mitigate exposure by preventing unauthenticated remote access to Spring Data projection-based request payload binding endpoints (e.g., restrict access to those endpoints via network controls/ACLs/WAF and require authentication).

Event History

May 11, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
May 16, 2018
Data Sourced
via Red Hat·03:00 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2018-1259?

CVE-2018-1259 is a vulnerability in Spring Data Commons.

2

How severe is CVE-2018-1259?

CVE-2018-1259 has a severity rating of 7.5 (high).

3

Which versions of Spring Data Commons are affected by CVE-2018-1259?

Versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7 of Spring Data Commons are affected by CVE-2018-1259.

4

How can I fix CVE-2018-1259?

To fix CVE-2018-1259, upgrade to version 1.13.12 or version 2.0.7 of Spring Data Commons.

5

Where can I find more information about CVE-2018-1259?

More information about CVE-2018-1259 can be found at the following references: [Link 1](https://pivotal.io/security/cve-2018-1259), [Link 2](https://jira.spring.io/browse/DATACMNS-1292), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1578939).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203