CVE-2018-1274: High severity Pivotal Software Spring Data Commons vulnerability
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.springframework.data:spring-data-commonsto a version that resolves this vulnerability.Fixed in 2.0.6 - Upgrade
Upgrade
maven/org.springframework.data:spring-data-commonsto a version that resolves this vulnerability.Fixed in 1.13.11
Event History
Frequently Asked Questions
What is CVE-2018-1274?
CVE-2018-1274 is a property path parser vulnerability in Spring Data Commons versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, allowing for unlimited resource allocation and potential remote code execution.
What is the severity of CVE-2018-1274?
CVE-2018-1274 has a severity rating of 7.5 (High).
How does CVE-2018-1274 impact Spring Data Commons?
CVE-2018-1274 allows an unauthenticated remote attacker to issue requests against Spring Data REST endpoints, potentially leading to remote code execution.
How can I fix CVE-2018-1274?
To fix CVE-2018-1274, it is recommended to update to a supported version of Spring Data Commons (1.13.11 or newer, 2.0.6 or newer) or Spring Data REST (2.6.11 or newer, 3.0.6 or newer).
Where can I find more information about CVE-2018-1274?
More information about CVE-2018-1274 can be found at the following references: [securityfocus.com](http://www.securityfocus.com/bid/103769), [pivotal.io](https://pivotal.io/security/cve-2018-1274), [oracle.com](https://www.oracle.com/security-alerts/cpujul2022.html).