VDB

CVE-2018-1259

CVE-2018-1259 PUBLISHED CVSS 7.5 HIGH

Reported by dell · Published May 11, 2018

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
PivotalSpring Data Commons1.13 prior to 1.13.12; 2.0 prior to 2.0.7
Mavenorg.xmlbeam:xmlprojector0, 0, 0
PivotalSpring Data Commons*, *, 1.13 prior to 1.13.12; 2.0 prior to 2.0.7
Mavenorg.springframework.data:spring-data-commons1.13.0, 1.13.0, 1.13.0

Timeline

  • May 11, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 23, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›