CVE-2018-1259: XEE
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/spring-data-commonsto a version that resolves this vulnerability.Fixed in 1.13.12 - Upgrade
Upgrade
redhat/spring-data-commonsto a version that resolves this vulnerability.Fixed in 2.0.7 - Upgrade
Upgrade
Spring Data Commonsto a version that resolves this vulnerability.Fixed in 1.13.12 - Upgrade
Upgrade
Spring Data Commonsto a version that resolves this vulnerability.Fixed in 2.0.7 - Compensating control
If upgrading is not immediately possible, mitigate exposure by preventing unauthenticated remote access to Spring Data projection-based request payload binding endpoints (e.g., restrict access to those endpoints via network controls/ACLs/WAF and require authentication).
Event History
Frequently Asked Questions
What is CVE-2018-1259?
CVE-2018-1259 is a vulnerability in Spring Data Commons.
How severe is CVE-2018-1259?
CVE-2018-1259 has a severity rating of 7.5 (high).
Which versions of Spring Data Commons are affected by CVE-2018-1259?
Versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7 of Spring Data Commons are affected by CVE-2018-1259.
How can I fix CVE-2018-1259?
To fix CVE-2018-1259, upgrade to version 1.13.12 or version 2.0.7 of Spring Data Commons.
Where can I find more information about CVE-2018-1259?
More information about CVE-2018-1259 can be found at the following references: [Link 1](https://pivotal.io/security/cve-2018-1259), [Link 2](https://jira.spring.io/browse/DATACMNS-1292), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1578939).