Pivotal Spring Framework CVE-2018-1272 Remote Privilege Escalation Vulnerability
BID:103697
CVE-2018-1272 |Info
Pivotal Spring Framework CVE-2018-1272 Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 103697 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1272 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 05 2018 12:00AM |
| Updated: | Apr 05 2018 12:00AM |
| Credit: | Philippe Arteau from GoSecure. |
| Vulnerable: |
Redhat JBoss Fuse 6.0 Redhat JBoss Fuse 7.0 Redhat JBoss A-MQ 6.0 Pivotal Spring Framework 5.0.4 Pivotal Spring Framework 5.0.3 Pivotal Spring Framework 5.0.2 Pivotal Spring Framework 5.0.1 Pivotal Spring Framework 5.0 Pivotal Spring Framework 4.3.14 Pivotal Spring Framework 4.3 |
| Not Vulnerable: |
Pivotal Spring Framework 5.0.5 Pivotal Spring Framework 4.3.15 |
Discussion
Pivotal Spring Framework CVE-2018-1272 Remote Privilege Escalation Vulnerability
Pivotal Spring Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges. Failed exploit attempts will likely result in denial-of-service conditions.
Spring Framework 5.0 through 5.0.4 and 4.3.x through 4.3.14 are vulnerable; prior unsupported versions may also be affected.
Pivotal Spring Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges. Failed exploit attempts will likely result in denial-of-service conditions.
Spring Framework 5.0 through 5.0.4 and 4.3.x through 4.3.14 are vulnerable; prior unsupported versions may also be affected.
References
Pivotal Spring Framework CVE-2018-1272 Remote Privilege Escalation Vulnerability
References:
References: