CVE-2018-1273
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
- Affected products
- Spring Data Commons
- Broadcom Spring Data Commons
- ≤ 1.12.10, 1.13.10, 2.0.5
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 95.7% (100th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2018-04-11
CVE-2018-1273 at NVD
15 known exploits for CVE-2018-1273
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2018-1273
poc-cve-2018-1273
poc-cve-2018-1273
cve-2018-1273
CVE-2018-1273
cve-2018-1273
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons
Spring Data Commons RCE
CVE-2018-1273: RCE with Spring Data Commons
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons