Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1275

Опубликовано: 09 апр. 2018
Источник: redhat
CVSS3: 9.8
EPSS Средний

Описание

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8springframeworkNot affected
Red Hat Fuse 7springNot affected
Red Hat JBoss A-MQ 6springNot affected
Red Hat JBoss BRMS 6springNot affected
Red Hat JBoss Data Virtualization 6springNot affected
Red Hat JBoss Enterprise Application Platform 5jbosswebNot affected
Red Hat JBoss Enterprise Application Platform 6jbosswebNot affected
Red Hat JBoss Enterprise Application Platform 7undertowNot affected
Red Hat JBoss Enterprise Web Server 2tomcatNot affected
Red Hat JBoss Fuse 6springAffected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1565307spring-framework: Address partial fix for CVE-2018-1270

EPSS

Процентиль: 97%
0.32447
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
nvd
около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
debian
около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 9.8
github
больше 6 лет назад

Spring Framework has Improperly Implemented Security Check for Standard

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость модуля spring-messaging программной платформы Spring Framework, позволяющая нарушителю получить полный контроль над приложением

EPSS

Процентиль: 97%
0.32447
Средний

9.8 Critical

CVSS3