5
CVSSv2

CVE-2018-1274

Published: 18/04/2018 Updated: 25/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software spring data commons

pivotal software spring data rest

Vendor Advisories

Spring Data Commons, versions 113 to 11310, 20 to 205, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a den ...