Multiple Pivotal Products CVE-2017-8046 Remote Code Execution Vulnerability
BID:100948
Info
Multiple Pivotal Products CVE-2017-8046 Remote Code Execution Vulnerability
| Bugtraq ID: | 100948 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-8046 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2017 12:00AM |
| Updated: | Sep 21 2017 12:00AM |
| Credit: | Man Yue Mo from Semmle and lgtm.com. |
| Vulnerable: |
Pivotal Spring Data REST 2.6.6 Pivotal Spring Data REST 2.6 Pivotal Spring Data REST 2.5.11 Pivotal Spring Data REST 2.5 Pivotal Spring Data REST 3.0 RC2 Pivotal Spring Data REST 3.0 RC1 Pivotal Spring Data Ingalls-SR7 Pivotal Spring Data Hopper-SR11 Pivotal Spring Boot 2.0 Pivotal Spring Boot 1.5.7 Pivotal Spring Boot 1.4.7 |
| Not Vulnerable: |
Pivotal Spring Data REST 2.6.7 Pivotal Spring Data REST 2.5.12 Pivotal Spring Data REST 3.0 RC3 Pivotal Spring Data Kay-RC3 Pivotal Spring Boot 2.0.0.M4 |
Discussion
Multiple Pivotal Products CVE-2017-8046 Remote Code Execution Vulnerability
Multiple Pivotal Products are prone to remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application. Failed exploits will result in denial-of-service conditions.
The following products are vulnerable:
Versions prior to Spring Data REST 2.5.12, 2.6.7, and 3.0 RC3
Versions prior to Spring Boot 2.0.0M4
Versions prior to Spring Data release trains prior to Kay-RC3
Multiple Pivotal Products are prone to remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application. Failed exploits will result in denial-of-service conditions.
The following products are vulnerable:
Versions prior to Spring Data REST 2.5.12, 2.6.7, and 3.0 RC3
Versions prior to Spring Boot 2.0.0M4
Versions prior to Spring Data release trains prior to Kay-RC3
Exploit / POC
Multiple Pivotal Products CVE-2017-8046 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Pivotal Products CVE-2017-8046 Remote Code Execution Vulnerability
References:
References:
- 2.6.7.RELEASE (Spring)
- Path expressions in JSON Patch allow references to non-properties (Spring)
- Pivotal Homepage (Pivotal)
- Spring Data REST Changelog (Spring)
- CVE-2017-8046: RCE in PATCH requests in Spring Data REST (Pivotal)