CVE-2018-1259
published 2018-05-11CVE-2018-1259: Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property…
PriorityP350high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
4.97%
91.2th percentile
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| broadcom | spring_data_commons | 1.13 – 1.13.11 | — |
| broadcom | spring_data_commons | 2.0 – 2.0.6 | — |
| pivotal | spring_data_commons | — | — |
| pivotal_software | spring_data_rest | 3.0 – 3.0.6 | — |
| vmware | spring_data_rest | <= 2.6.11 | — |
| xmlbeam | xmlbeam | <= 1.4.14 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
ghsa·2018-10-17
CVE-2018-1259 [HIGH] CWE-611 Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
OSV
Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
osv·2018-10-17
CVE-2018-1259 [HIGH] Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Red Hat
spring-data-commons: XXE with Spring Data’s XMLBeam integration
vendor_redhat·2018-05-09·CVSS 7.5
CVE-2018-1259 [HIGH] CWE-611 spring-data-commons: XXE with Spring Data’s XMLBeam integration
spring-data-commons: XXE with Spring Data’s XMLBeam integration
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Package: spring-data-commons (Red Hat JBoss Fuse 6) - Not affected
Package: spring-data-commons (Red Hat JBoss Fuse Integration Service 2) - Not affected
Package: spring-data-commons (Red Hat Mobile Application Platfor
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1259 springframework-data-commons: spring-data-commons: XXE with Spring Data’s XMLBeam integration [fedora-all]
bugzilla·2018-05-16·CVSS 7.5
CVE-2018-1259 [HIGH] CVE-2018-1259 springframework-data-commons: spring-data-commons: XXE with Spring Data’s XMLBeam integration [fedora-all]
CVE-2018-1259 springframework-data-commons: spring-data-commons: XXE with Spring Data’s XMLBeam integration [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2018-1259 spring-data-commons: XXE with Spring Data’s XMLBeam integration
bugzilla·2018-05-16·CVSS 7.5
CVE-2018-1259 [HIGH] CVE-2018-1259 spring-data-commons: XXE with Spring Data’s XMLBeam integration
CVE-2018-1259 spring-data-commons: XXE with Spring Data’s XMLBeam integration
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
References:
https://pivotal.io/security/cve-2018-1259
https://jira.spring.io/browse/DATACMNS-1292
Discussion:
Created springframework-data-commons tracking bugs for this issue:
Affects: fedora-all [bug
https://access.redhat.com/errata/RHSA-2018:1809https://access.redhat.com/errata/RHSA-2018:3768https://pivotal.io/security/cve-2018-1259https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://access.redhat.com/errata/RHSA-2018:1809https://access.redhat.com/errata/RHSA-2018:3768https://pivotal.io/security/cve-2018-1259https://www.oracle.com/security-alerts/cpujul2022.html
2018-05-11
Published