CVE-2018-1259

CVSS v3.0 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.37 % (73th)
0.37% Progress
Affected Products 3
Advisories 1

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Weaknesses
CWE-611
Improper Restriction of XML External Entity Reference
CVE Status
PUBLISHED
CNA
Dell
Published Date
2018-05-11 20:29:00
(6 years ago)
Updated Date
2022-07-25 18:15:14
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Pivotal Software Spring Data Commons from 1.13 version and 1.13.11 and prior versions cpe:2.3:a:pivotal_software:spring_data_commons >= 1.13 <= 1.13.11
  Pivotal Software Spring Data Commons from 2.0 version and 2.0.6 and prior versions cpe:2.3:a:pivotal_software:spring_data_commons >= 2.0 <= 2.0.6

Configuration #2

    CPE23 From Up To
  Pivotal Software Spring Data Rest above 2.6 version and 2.6.11 and prior versions cpe:2.3:a:pivotal_software:spring_data_rest > 2.6 <= 2.6.11
  Pivotal Software Spring Data Rest from 3.0 version and 3.0.6 and prior versions cpe:2.3:a:pivotal_software:spring_data_rest >= 3.0 <= 3.0.6

Configuration #3

    CPE23 From Up To
  Xmlbeam 1.4.14 and prior versions cpe:2.3:a:xmlbeam:xmlbeam <= 1.4.14
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...