Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Aug 2024 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2018-04-11T13:00:00Z
Updated: 2024-09-16T20:32:59.445Z
Reserved: 2017-12-06T00:00:00
Link: CVE-2018-1273
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-04-11T13:29:00.290
Modified: 2024-11-21T03:59:31.063
Link: CVE-2018-1273
Redhat