← All CVEs

CVE-2018-1273

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-25Remediation due 2022-04-15

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

9.8
CVSS
97.0%
EPSS (exploit prob.)
100th
EPSS percentile
2018-04-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
broadcomspring_data_commons<= 1.12.10
broadcomspring_data_commons>= 1.13.0, <= 1.13.10
broadcomspring_data_commons>= 2.0.0, <= 2.0.5
pivotal_softwarespring_data_rest>= 3.0.0, <= 3.0.5
vmwarespring_data_rest<= 2.5.10
vmwarespring_data_rest>= 2.6.0, <= 2.6.10
apacheignite>= 1.0.1, <= 2.5.0
apacheignite1.0.0
apacheignite1.0.0
oraclefinancial_services_crime_and_compliance_management_studio8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio8.0.8.3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1273