cbcvebase.
CVE-2018-1259
published 2018-05-11

CVE-2018-1259: Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property…

PriorityP350high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
4.97%
91.2th percentile
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Affected

6 ranges
VendorProductVersion rangeFixed in
broadcomspring_data_commons1.13 – 1.13.11
broadcomspring_data_commons2.0 – 2.0.6
pivotalspring_data_commons
pivotal_softwarespring_data_rest3.0 – 3.0.6
vmwarespring_data_rest<= 2.6.11
xmlbeamxmlbeam<= 1.4.14

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.