CVE-2018-1275
published 2018-04-11CVE-2018-1275: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
57.63%
99.0th percentile
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | big_data_discovery | — | — |
| oracle | communications_converged_application_server | < 7.0.0.1 | 7.0.0.1 |
| oracle | communications_diameter_signaling_router | < 8.3 | 8.3 |
| oracle | communications_performance_intelligence_center | < 10.2.1 | 10.2.1 |
| oracle | communications_services_gatekeeper | < 6.1.0.4.0 | 6.1.0.4.0 |
| oracle | goldengate_for_big_data | — | — |
| oracle | goldengate_for_big_data | — | — |
| oracle | goldengate_for_big_data | — | — |
| oracle | health_sciences_information_manager | — | — |
| oracle | healthcare_master_person_index | — | — |
| oracle | healthcare_master_person_index | — | — |
| oracle | insurance_calculation_engine | — | — |
| oracle | insurance_calculation_engine | — | — |
| oracle | insurance_calculation_engine | — | — |
| oracle | insurance_rules_palette | — | — |
| oracle | insurance_rules_palette | — | — |
| oracle | insurance_rules_palette | — | — |
| oracle | insurance_rules_palette | — | — |
| oracle | insurance_rules_palette | — | — |
| oracle | primavera_gateway | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/spring-projects/spring-framework/commit/0009806debb578e884f6dc98bd1f2dc668020021↗
urlhttps://github.com/spring-projects/spring-framework/commit/e0de9126ed8cf25cf141d3e66420da94e350708a↗
- →Monitor for crafted STOMP messages sent over WebSocket endpoints to the spring-messaging in-memory STOMP broker, which can be used to trigger remote code execution. ↗
- →This CVE is a bypass/incomplete fix for CVE-2018-1270 specifically in the 4.3.x branch; detection logic for CVE-2018-1270 STOMP RCE payloads should also be applied to Spring Framework 4.3.x versions prior to 4.3.16. ↗
- →CVE-2018-1270, which permitted a malicious user to craft a STOMP message that could lead to remote code execution, was not fully addressed in the 4.3.x branch; treat 4.3.x deployments as still vulnerable until patched to 4.3.16+. ↗
- ·Vulnerable only when applications expose STOMP over WebSocket endpoints using the spring-messaging module with a simple, in-memory STOMP broker. Applications not using this configuration are not affected. ↗
- ·Affected versions are Spring Framework 5.0 prior to 5.0.5 and 4.3 prior to 4.3.16. The 4.3.15 fix for CVE-2018-1270 was incomplete, making 4.3.15 still vulnerable. ↗
- ·Red Hat Fuse 6.3 and Fuse Integration Services 2.0 are not directly affected but reference affected Spring versions in their Camel-Springboot Maven BOM; users pulling Spring STOMP messaging from those repositories should update BOMs. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Spring Framework has Improperly Implemented Security Check for Standard
osv·2018-10-17·CVSS 9.8
CVE-2018-1275 [CRITICAL] Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
GHSA
Spring Framework has Improperly Implemented Security Check for Standard
ghsa·2018-10-17·CVSS 9.8
CVE-2018-1275 [CRITICAL] CWE-358 Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework has Improperly Implemented Security Check for Standard
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Red Hat
spring-framework: Address partial fix for CVE-2018-1270
vendor_redhat·2018-04-09·CVSS 9.8
CVE-2018-1275 [CRITICAL] CWE-20 spring-framework: Address partial fix for CVE-2018-1270
spring-framework: Address partial fix for CVE-2018-1270
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Package: springframework (Red Hat Enterprise Linux 8) - Not affected
Package: spring (Red Hat Fuse 7) - Not affected
Package: spring (Red Hat JBoss A-MQ 6) - Not affected
Package: spring (Red Hat JBoss BRMS 6) - Not affected
Package: spring (Red Hat JBoss Data Virtualization 6) -
Debian
CVE-2018-1275: libspring-java - Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 a...
vendor_debian·2018·CVSS 9.8
CVE-2018-1275 [CRITICAL] CVE-2018-1275: libspring-java - Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 a...
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1275 spring-framework: Address partial fix for CVE-2018-1270
bugzilla·2018-04-09·CVSS 9.8
CVE-2018-1275 [CRITICAL] CVE-2018-1275 spring-framework: Address partial fix for CVE-2018-1270
CVE-2018-1275 spring-framework: Address partial fix for CVE-2018-1270
CVE-2018-1270, which permitted a malicious user to craft a STOMP message that could lead to remote code execution, was not fully addressed in the 4.3.x branch of the Spring Framework.
Discussion:
Upstream commit: https://github.com/spring-projects/spring-framework/commit/0009806debb578e884f6dc98bd1f2dc668020021
---
This issue has been addressed in the following products:
Red Hat Openshift Application Runtimes
Via RHSA-2018:1320 https://access.redhat.com/errata/RHSA-2018:1320
---
This issue has been addressed in the following products:
Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8
Via RHSA-2018:2939 https://access.redhat.com/errata/RHSA-2018:2939
Bugzilla
CVE-2018-1270 spring-framework: Possible RCE via spring messaging
bugzilla·2018-04-06·CVSS 9.8
CVE-2018-1270 [CRITICAL] CVE-2018-1270 spring-framework: Possible RCE via spring messaging
CVE-2018-1270 spring-framework: Possible RCE via spring messaging
Spring Framework allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
External References:
https://pivotal.io/security/cve-2018-1270
Discussion:
Created springframework tracking bugs for this issue:
Affects: fedora-all [bug 1564409]
---
Upstream fix (5.0.5): https://github.com/spring-projects/spring-framework/commit/e0de9126ed8cf25cf141d3e66420da94e350708a
The fix in 4.3.15 was incomplete, and a new CVE issued: CVE-2018-1275.
---
Statement:
No Red Hat products are directly affected by this flaw; the products that package
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/103771http://www.securitytracker.com/id/1041301https://access.redhat.com/errata/RHSA-2018:1320https://access.redhat.com/errata/RHSA-2018:2939https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3Ehttps://pivotal.io/security/cve-2018-1275https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/103771http://www.securitytracker.com/id/1041301https://access.redhat.com/errata/RHSA-2018:1320https://access.redhat.com/errata/RHSA-2018:2939https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3Ehttps://pivotal.io/security/cve-2018-1275https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-04-11
Published