Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m929-7fr6-cvjg Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T16:33:36.641Z

Reserved: 2017-12-06T00:00:00

Link: CVE-2018-1259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-11T20:29:00.307

Modified: 2024-11-21T03:59:29.177

Link: CVE-2018-1259

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-05-09T00:00:00Z

Links: CVE-2018-1259 - Bugzilla

cve-icon OpenCVE Enrichment

No data.