CVE-2018-1270
Severity
9.8CRITICAL
EPSS
90.0%
top 0.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 6
Latest updateOct 17
Description
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages30 packages
▶CVEListV5spring_by_pivotal/spring_frameworkVersions prior to 5.0.5 and 4.3.15, Versions prior to 5.0.5 and 4.3.16+1
Also affects: Debian Linux 9.0