Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2018-05-11T20:00:00Z

Updated: 2024-09-16T16:33:36.641Z

Reserved: 2017-12-06T00:00:00

Link: CVE-2018-1259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-11T20:29:00.307

Modified: 2022-07-25T18:15:14.550

Link: CVE-2018-1259

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-05-09T00:00:00Z

Links: CVE-2018-1259 - Bugzilla