CVE-2018-1270
published 2018-04-06CVE-2018-1270: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over…
PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
77.24%
99.5th percentile
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libspring-java | < libspring-java 4.3.19-1 (bookworm) | libspring-java 4.3.19-1 (bookworm) |
| debian | libspring-java | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | big_data_discovery | — | — |
| oracle | communications_converged_application_server | < 7.0.0.1 | 7.0.0.1 |
| oracle | communications_diameter_signaling_router | < 8.3 | 8.3 |
| oracle | communications_performance_intelligence_center | < 10.2.1 | 10.2.1 |
| oracle | communications_services_gatekeeper | < 6.1.0.4.0 | 6.1.0.4.0 |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | goldengate_for_big_data | — | — |
| oracle | goldengate_for_big_data | — | — |
| oracle | goldengate_for_big_data | — | — |
| oracle | health_sciences_information_manager | — | — |
| oracle | healthcare_master_person_index | — | — |
| oracle | healthcare_master_person_index | — | — |
| oracle | insurance_calculation_engine | — | — |
| oracle | insurance_calculation_engine | — | — |
| oracle | insurance_calculation_engine | — | — |
| oracle | insurance_rules_palette | — | — |
| oracle | insurance_rules_palette | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/spring-projects/spring-framework/commit/e0de9126ed8cf25cf141d3e66420da94e350708a↗
- →Exploit vector targets STOMP over WebSocket endpoints using the spring-messaging module's simple in-memory STOMP broker; monitor for crafted STOMP messages delivered over WebSocket connections to Spring-based applications. ↗
- →Detection should focus on Spring Framework deployments exposing STOMP/WebSocket endpoints (spring-messaging module); versions 5.0 prior to 5.0.5 and 4.3 prior to 4.3.15 are vulnerable. ↗
- ·The fix shipped in Spring Framework 4.3.15 for CVE-2018-1270 was incomplete; a separate CVE (CVE-2018-1275) was issued to track the remaining exposure in the 4.3.x branch. Ensure 4.3.x deployments are patched to at least 4.3.16. ↗
- ·Red Hat Fuse 6.3 and Fuse Integration Services 2.0 are not directly affected but reference vulnerable Spring versions in their Camel-Springboot Maven BOM; consumers of those BOMs should update when new BOMs are available. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Spring Framework has Improperly Implemented Security Check for Standard
osv·2018-10-17·CVSS 9.8
CVE-2018-1275 [CRITICAL] Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
OSV
Spring Framework allows applications to expose STOMP over WebSocket endpoints
osv·2018-10-17
CVE-2018-1270 [CRITICAL] Spring Framework allows applications to expose STOMP over WebSocket endpoints
Spring Framework allows applications to expose STOMP over WebSocket endpoints
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
GHSA
Spring Framework has Improperly Implemented Security Check for Standard
ghsa·2018-10-17·CVSS 9.8
CVE-2018-1275 [CRITICAL] CWE-358 Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
GHSA
Spring Framework allows applications to expose STOMP over WebSocket endpoints
ghsa·2018-10-17
CVE-2018-1270 [CRITICAL] CWE-358 Spring Framework allows applications to expose STOMP over WebSocket endpoints
Spring Framework allows applications to expose STOMP over WebSocket endpoints
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
OSV
CVE-2018-1270: Spring Framework, versions 5
osv·2018-04-06·CVSS 9.8
CVE-2018-1270 [CRITICAL] CVE-2018-1270: Spring Framework, versions 5
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Red Hat
spring-framework: Address partial fix for CVE-2018-1270
vendor_redhat·2018-04-09·CVSS 9.8
CVE-2018-1275 [CRITICAL] CWE-20 spring-framework: Address partial fix for CVE-2018-1270
spring-framework: Address partial fix for CVE-2018-1270
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Package: springframework (Red Hat Enterprise Linux 8) - Not affected
Package: spring (Red Hat Fuse 7) - Not affected
Package: spring (Red Hat JBoss A-MQ 6) - Not affected
Package: spring (Red Hat JBoss BRMS 6) - Not affected
Package: spring (Red Hat JBoss Data Virtualization 6) -
Red Hat
spring-framework: Possible RCE via spring messaging
vendor_redhat·2018-04-05·CVSS 9.8
CVE-2018-1270 [CRITICAL] CWE-20 spring-framework: Possible RCE via spring messaging
spring-framework: Possible RCE via spring messaging
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Statement: No Red Hat products are directly affected by this flaw; the products that package some parts of the Spring Framework either do not ship the affected messaging component, or use an older version that is not affected.
Fuse 6.3 and Fuse Integration Services 2.0 are both not directly affected by the flaw, but both point to the affected versions in their respective Camel-Spring
Debian
CVE-2018-1270: libspring-java - Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 a...
vendor_debian·2018·CVSS 9.8
CVE-2018-1270 [CRITICAL] CVE-2018-1270: libspring-java - Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 a...
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Scope: local
bookworm: resolved (fixed in 4.3.19-1)
bullseye: resolved (fixed in 4.3.19-1)
forky: resolved (fixed in 4.3.19-1)
sid: resolved (fixed in 4.3.19-1)
trixie: resolved (fixed in 4.3.19-1)
Debian
CVE-2018-1275: libspring-java - Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 a...
vendor_debian·2018·CVSS 9.8
CVE-2018-1275 [CRITICAL] CVE-2018-1275: libspring-java - Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 a...
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1275 spring-framework: Address partial fix for CVE-2018-1270
bugzilla·2018-04-09·CVSS 9.8
CVE-2018-1275 [CRITICAL] CVE-2018-1275 spring-framework: Address partial fix for CVE-2018-1270
CVE-2018-1275 spring-framework: Address partial fix for CVE-2018-1270
CVE-2018-1270, which permitted a malicious user to craft a STOMP message that could lead to remote code execution, was not fully addressed in the 4.3.x branch of the Spring Framework.
Discussion:
Upstream commit: https://github.com/spring-projects/spring-framework/commit/0009806debb578e884f6dc98bd1f2dc668020021
---
This issue has been addressed in the following products:
Red Hat Openshift Application Runtimes
Via RHSA-2018:1320 https://access.redhat.com/errata/RHSA-2018:1320
---
This issue has been addressed in the following products:
Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8
Via RHSA-2018:2939 https://access.redhat.com/errata/RHSA-2018:2939
Bugzilla
CVE-2018-1270 CVE-2018-1272 springframework: various flaws [fedora-all]
bugzilla·2018-04-06·CVSS 9.8
CVE-2018-1270 [CRITICAL] CVE-2018-1270 CVE-2018-1272 springframework: various flaws [fedora-all]
CVE-2018-1270 CVE-2018-1272 springframework: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2018-1270 spring-framework: Possible RCE via spring messaging
bugzilla·2018-04-06·CVSS 9.8
CVE-2018-1270 [CRITICAL] CVE-2018-1270 spring-framework: Possible RCE via spring messaging
CVE-2018-1270 spring-framework: Possible RCE via spring messaging
Spring Framework allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
External References:
https://pivotal.io/security/cve-2018-1270
Discussion:
Created springframework tracking bugs for this issue:
Affects: fedora-all [bug 1564409]
---
Upstream fix (5.0.5): https://github.com/spring-projects/spring-framework/commit/e0de9126ed8cf25cf141d3e66420da94e350708a
The fix in 4.3.15 was incomplete, and a new CVE issued: CVE-2018-1275.
---
Statement:
No Red Hat products are directly affected by this flaw; the products that package
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/103696https://access.redhat.com/errata/RHSA-2018:2939https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/04/msg00022.htmlhttps://pivotal.io/security/cve-2018-1270https://www.exploit-db.com/exploits/44796/https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/103696https://access.redhat.com/errata/RHSA-2018:2939https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/04/msg00022.htmlhttps://pivotal.io/security/cve-2018-1270https://www.exploit-db.com/exploits/44796/https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-04-06
Published