5
CVSSv2

CVE-2018-1259

Published: 11/05/2018 Updated: 25/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Spring Data Commons, versions 1.13 before 1.13.12 and 2.0 before 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software spring data commons

pivotal software spring data rest

xmlbeam xmlbeam

Vendor Advisories

Synopsis Important: Red Hat OpenShift Application Runtimes Spring Boot security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Application RuntimesRed Hat Product Security has rated this update as having a security impact of Important A ...
Synopsis Important: Red Hat Fuse 72 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat FuseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a de ...
Spring Data Commons, versions 113 prior to 11312 and 20 prior to 207, used in combination with XMLBeam 1414 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion An unauthenticated remote mal ...