CVE-2018-1257
published 2018-05-11CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
3.24%
86.9th percentile
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 4.3.19-1 (bookworm) | libspring-java 4.3.19-1 (bookworm) |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | big_data_discovery | — | — |
| oracle | communications_converged_application_server | < 7.0.0.1 | 7.0.0.1 |
| oracle | communications_diameter_signaling_router | < 8.3 | 8.3 |
| oracle | communications_performance_intelligence_center | < 10.2.1 | 10.2.1 |
| oracle | communications_services_gatekeeper | < 6.1.0.4.0 | 6.1.0.4.0 |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | endeca_information_discovery_integrator | — | — |
| oracle | endeca_information_discovery_integrator | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_for_mysql_database | — | — |
| oracle | enterprise_manager_ops_center | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of Service in org.springframework:spring-core
osv·2018-10-17
CVE-2018-1257 [MEDIUM] Denial of Service in org.springframework:spring-core
Denial of Service in org.springframework:spring-core
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
GHSA
Denial of Service in org.springframework:spring-core
ghsa·2018-10-17
CVE-2018-1257 [MEDIUM] Denial of Service in org.springframework:spring-core
Denial of Service in org.springframework:spring-core
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
OSV
CVE-2018-1257: Spring Framework, versions 5
osv·2018-05-11·CVSS 6.5
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Red Hat
spring-framework: ReDoS Attack with spring-messaging
vendor_redhat·2018-05-09·CVSS 6.5
CVE-2018-1257 [MEDIUM] CWE-200 spring-framework: ReDoS Attack with spring-messaging
spring-framework: ReDoS Attack with spring-messaging
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Package: spring (Red Hat JBoss A-MQ 6) - Not affected
Package: spring (Red Hat JBoss BRMS 5) - Not affected
Package: spring (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: spring (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: spring (Red Hat JBoss Fuse 6) - Not affected
Package: spring (Red Hat JBoss Fuse Integr
Debian
CVE-2018-1257: libspring-java - Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17,...
vendor_debian·2018·CVSS 6.5
CVE-2018-1257 [MEDIUM] CVE-2018-1257: libspring-java - Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17,...
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Scope: local
bookworm: resolved (fixed in 4.3.19-1)
bullseye: resolved (fixed in 4.3.19-1)
forky: resolved (fixed in 4.3.19-1)
sid: resolved (fixed in 4.3.19-1)
trixie: resolved (fixed in 4.3.19-1)
No detection rules found.
Bugzilla
CVE-2018-11125 rapidjson: Heap-based buffer over-read in the Peek function in stream.h
bugzilla·2018-05-17
CVE-2018-11125 [LOW] CVE-2018-11125 rapidjson: Heap-based buffer over-read in the Peek function in stream.h
CVE-2018-11125 rapidjson: Heap-based buffer over-read in the Peek function in stream.h
Tencent RapidJSON 1.1.0 has a heap-based buffer over-read in the Peek function in stream.h.
Upstream issue:
https://github.com/Tencent/rapidjson/issues/1257
Discussion:
This has been rejected as an invalid issue by upstream.
https://github.com/Tencent/rapidjson/issues/1257#issuecomment-389325604
Bugzilla
CVE-2018-1257 springframework: spring-framework: ReDoS Attack with spring-messaging [fedora-all]
bugzilla·2018-05-15·CVSS 6.5
CVE-2018-1257 [MEDIUM] CVE-2018-1257 springframework: spring-framework: ReDoS Attack with spring-messaging [fedora-all]
CVE-2018-1257 springframework: spring-framework: ReDoS Attack with spring-messaging [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2018-1257 spring-framework: ReDoS Attack with spring-messaging
bugzilla·2018-05-15·CVSS 6.5
CVE-2018-1257 [MEDIUM] CVE-2018-1257 spring-framework: ReDoS Attack with spring-messaging
CVE-2018-1257 spring-framework: ReDoS Attack with spring-messaging
A flaw was found in Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
References:
https://pivotal.io/security/cve-2018-1257
Discussion:
Created springframework tracking bugs for this issue:
Affects: fedora-all [bug 1578579]
---
RHMAP doesn't make sure of websocket stomp as described in https://docs.spring.io/spring/docs/current/spring-framework-reference/web.html#websocket-stomp-enable
Marking
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104260https://access.redhat.com/errata/RHSA-2018:1809https://access.redhat.com/errata/RHSA-2018:3768https://pivotal.io/security/cve-2018-1257https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104260https://access.redhat.com/errata/RHSA-2018:1809https://access.redhat.com/errata/RHSA-2018:3768https://pivotal.io/security/cve-2018-1257https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-05-11
Published