CVE-2018-1196
Summary
| CVE | CVE-2018-1196 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-19 18:29:00 UTC |
| Updated | 2022-04-07 15:03:00 UTC |
| Description | Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the "run_user" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Spring Boot | 2.0.0 | m1 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m2 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m3 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m4 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m5 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m6 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m7 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m1 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m2 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m3 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m4 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m5 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m6 | All | All |
| Application | Pivotal Software | Spring Boot | 2.0.0 | m7 | All | All |
| Application | Pivotal Software | Spring Boot | All | All | All | All |
| Application | Vmware | Spring Boot | 2.0.0 | milestone1 | All | All |
| Application | Vmware | Spring Boot | 2.0.0 | milestone2 | All | All |
| Application | Vmware | Spring Boot | 2.0.0 | milestone3 | All | All |
| Application | Vmware | Spring Boot | 2.0.0 | milestone4 | All | All |
| Application | Vmware | Spring Boot | 2.0.0 | milestone5 | All | All |
| Application | Vmware | Spring Boot | 2.0.0 | milestone6 | All | All |
| Application | Vmware | Spring Boot | 2.0.0 | milestone7 | All | All |
| Application | Vmware | Spring Boot | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2018-1196: Symlink privilege escalation attack via Spring Boot launch script | Security | VMware Tanzu | CONFIRM | pivotal.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980770 Java (maven) Security Update for org.springframework.boot:spring-boot (GHSA-xx65-cc7g-9pfp)