Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1274

Опубликовано: 04 апр. 2018
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7spring-data-commonsAffected
Red Hat JBoss Fuse 6spring-data-commonsNot affected
Red Hat JBoss Fuse Integration Service 2spring-data-commonsNot affected
Red Hat Mobile Application Platform 4spring-data-commonsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-138
https://bugzilla.redhat.com/show_bug.cgi?id=1565926spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of service

EPSS

Процентиль: 76%
0.00967
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 8 лет назад

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

CVSS3: 7.5
github
больше 7 лет назад

Spring Data Commons contain a property path parser vulnerability caused by unlimited resource allocation

EPSS

Процентиль: 76%
0.00967
Низкий

7.5 High

CVSS3