CVE-2018-1273: VMware Tanzu Spring Data Commons Property Binder Vulnerability
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
Other sources
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding that can lead to a remote code execution attack.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.springframework.data:spring-data-commonsto a version that resolves this vulnerability.Fixed in 2.0.6 - Upgrade
Upgrade
maven/org.springframework.data:spring-data-commonsto a version that resolves this vulnerability.Fixed in 1.13.11 - Upgrade
Upgrade
Spring Data Commonsto a version that resolves this vulnerability.Fixed in 1.13.10 - Upgrade
Upgrade
Spring Data Commonsto a version that resolves this vulnerability.Fixed in 2.0.5
Event History
Frequently Asked Questions
What is CVE-2018-1273?
CVE-2018-1273 is a vulnerability in VMware Tanzu Spring Data Commons that allows an unauthenticated remote attacker to supply specially crafted request parameters.
Who is affected by CVE-2018-1273?
Users of VMware Tanzu Spring Data Commons versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions are affected.
What is the severity of CVE-2018-1273?
CVE-2018-1273 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2018-1273?
An attacker can exploit CVE-2018-1273 by supplying specially crafted request parameters.
Where can I find more information about CVE-2018-1273?
You can find more information about CVE-2018-1273 at the following references: [Reference 1](http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E), [Reference 2](https://pivotal.io/security/cve-2018-1273), [Reference 3](https://www.oracle.com/security-alerts/cpujul2022.html).