VDB
CVE-2018-1259
CVE-2018-1259
PUBLISHED
CVSS 7.5 HIGH
Reported by dell · Published May 11, 2018
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal | Spring Data Commons | 1.13 prior to 1.13.12; 2.0 prior to 2.0.7 |
| Maven | org.xmlbeam:xmlprojector | 0, 0, 0 |
| Pivotal | Spring Data Commons | *, *, 1.13 prior to 1.13.12; 2.0 prior to 2.0.7 |
| Maven | org.springframework.data:spring-data-commons | 1.13.0, 1.13.0, 1.13.0 |
Timeline
- May 11, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 23, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 12, 2023 EPSS Score
References
- RHSA-2018:1809 vendor-advisoryx_refsource_REDHAT
- RHSA-2018:3768 vendor-advisoryx_refsource_REDHAT
- x_refsource_MISC
- x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2018-1259 advisory
- https://github.com/advisories/GHSA-m929-7fr6-cvjg advisory