Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1273

Опубликовано: 27 мар. 2018
Источник: redhat
CVSS3: 9.8

Описание

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7spring-data-commonsAffected
Red Hat JBoss Fuse 6spring-data-commonsNot affected
Red Hat JBoss Fuse Integration Service 2spring-data-commonsNot affected
Red Hat Mobile Application Platform 4spring-data-commonsNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-138
https://bugzilla.redhat.com/show_bug.cgi?id=1565923spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 8 лет назад

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

CVSS3: 9.8
github
больше 7 лет назад

Spring Data Commons remote code injection vulnerability

CVSS3: 9.8
fstec
почти 8 лет назад

Уязвимость класса SimpleEvaluationContext платформы управления данными Spring Data Commons и фреймворка для создания веб-сервисов Spring Data REST, позволяющая нарушителю выполнить произвольный код

9.8 Critical

CVSS3