Junglewise Threat Intelligence

CVE-2018-1273: Spring Data Commons remote code injection vulnerability

CVE-2018-1273 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2018-10-17

Vendors: Apache.

Executive brief

Spring Data Commons contains a property binder vulnerability due to improper neutralization of special elements. An unauthenticated remote attacker can use specially crafted request parameters against Spring Data REST backed HTTP resources or projection-based request payload binding to achieve remote code execution.

Affected products

  • VMware Tanzu Spring Data Commons prior to 1.13.11, 2.0 to 2.0.6, and older unsupported versions
  • VMware Tanzu Spring Data REST up to 2.5.10, 2.6.0 to 2.6.10, 3.0.0 to 3.0.5
  • Apache Ignite 1.0.0 to 2.5.0

Timeline

  • 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-03-25: disclosed