CVE-2018-1273
Summary
| CVE | CVE-2018-1273 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-11 13:29:00 UTC |
| Updated | 2022-07-25 18:15:00 UTC |
| Description | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack. |
Risk And Classification
EPSS: 0.942880000 probability, percentile 0.999400000 (date 2026-04-01)
CISA KEV: Listed on 2022-03-25; due 2022-04-15; ransomware use Known
Problem Types: CWE-20
CISA Known Exploited Vulnerability
| Vendor | VMware Tanzu |
|---|---|
| Product | Spring Data Commons |
| Name | VMware Tanzu Spring Data Commons Property Binder Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-1273 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Ignite | 1.0.0 | rc3 | All | All |
| Application | Apache | Ignite | 1.0.0 | rc3 | All | All |
| Application | Apache | Ignite | All | All | All | All |
| Application | Pivotal Software | Spring Data Commons | All | All | All | All |
| Application | Pivotal Software | Spring Data Commons | All | All | All | All |
| Application | Pivotal Software | Spring Data Commons | All | All | All | All |
| Application | Pivotal Software | Spring Data Rest | All | All | All | All |
| Application | Pivotal Software | Spring Data Rest | All | All | All | All |
| Application | Pivotal Software | Spring Data Rest | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [CVE-2018-1273] Apache Ignite impacted by security vulnerability in Spring Data Commons | MLIST | mail-archives.apache.org | Mailing List, Third Party Advisory |
| CVE-2018-1273: RCE with Spring Data Commons | Security | VMware Tanzu | CONFIRM | pivotal.io | Vendor Advisory |
| Oracle Critical Patch Update Advisory - July 2022 | N/A | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983145 Java (maven) Security Update for org.springframework.data:spring-data-commons (GHSA-4fq3-mr56-cg6r)