Severity
9.8CRITICAL
EPSS
90.0%
top 0.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateOct 17

Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages30 packages

Mavenorg.springframework:spring-messaging5.0.0.RELEASE5.0.5.RELEASE+1
NVDvmware/spring_framework5.0.05.0.5+1
CVEListV5spring_by_pivotal/spring_frameworkVersions prior to 5.0.5 and 4.3.15, Versions prior to 5.0.5 and 4.3.16+1
Debianlibspring-java< 4.3.19-1+3
NVDoracle/retail_order_broker4 versions+3

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

5
OSV
Spring Framework allows applications to expose STOMP over WebSocket endpoints2018-10-17
GHSA
Spring Framework allows applications to expose STOMP over WebSocket endpoints2018-10-17
GHSA
Spring Framework has Improperly Implemented Security Check for Standard2018-10-17
OSV
CVE-2018-1270: Spring Framework, versions 52018-04-06
CVEList
CVE-2018-1270: Spring Framework, versions 52018-04-06

📋Vendor Advisories

3
Red Hat
spring-framework: Address partial fix for CVE-2018-12702018-04-09
Red Hat
spring-framework: Possible RCE via spring messaging2018-04-05
Debian
CVE-2018-1270: libspring-java - Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 a...2018

💬Community

3
Bugzilla
CVE-2018-1275 spring-framework: Address partial fix for CVE-2018-12702018-04-09
Bugzilla
CVE-2018-1270 CVE-2018-1272 springframework: various flaws [fedora-all]2018-04-06
Bugzilla
CVE-2018-1270 spring-framework: Possible RCE via spring messaging2018-04-06