Back

CRITICAL

spring-framework: Possible RCE via spring messaging

Published Apr 6, 2018

Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.

Affected products

Remediation

Red Hat statement

No Red Hat products are directly affected by this flaw; the products that package some parts of the Spring Framework either do not ship the affected messaging component, or use an older version that is not affected. Fuse 6.3 and Fuse Integration Services 2.0 are both not directly affected by the flaw, but both point to the affected versions in their respective Camel-Springboot Maven repository BOMs. Fixes for those repository links will be addressed in advisories via regular patch cycle; customers using Spring stomp messaging from these Maven repositories are advised to update to the new BOMs when available.

Metrics

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Apr 6, 2018
Updated Sep 16, 2024
Reserved Dec 6, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Apr 5, 2018
GHSA-P5HG-3XM3-GCJG