spring-framework: Possible RCE via spring messaging
Published Apr 6, 2018
9.8
CRITICALCVSS 3.1
EPSS 77.48%
Description
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Affected products
-
- Version Versions prior to 5.0.5 and 4.3.15StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring by Pivotal | Spring Framework | n/a |
|
Configuration 1
- < 4.3.16
- ≥ 5.0.0 · < 5.0.5
Configuration 2
- 12.5.0.3
- 13.1.0.1
- 13.2.0.1
- 13.3.0.1
- 1.6.0
- < 7.0.0.1
- < 8.3
- < 10.2.1
- < 6.1.0.4.0
- 12.2.2
- 12.3.3
- 12.2.0.1
- 12.3.1.1
- 12.3.2.1
- 3.0
- 3.0
- 4.0
- 10.1.1
- 10.2
- 10.2.1
- 10.0
- 10.1
- 10.2
- 11.0
- 11.1
- 15.2
- 16.2
- 17.12
- 14.0
- 14.1
- 14.0
- 14.1
- 15.0
- 16.0
- 14.0.1
- 14.0.2
- 14.0.3
- 14.0.4
- 14.1.1
- 14.1.2
- 14.1.3
- 15.0.0.1
- 15.0.1
- 15.0.2
- 16.0
- 16.0.1
- 16.0.2
- 5.3.0
- 6.0.0
- 6.0.1
- 5.1
- 5.2
- 15.0
- 16.0
- 14.0
- 14.1
- 14.0
- 14.1
- 15.0
- 16.0
- 14.0
- 14.1
- 7.1
- 12.1.3.0.0
- 12.2.2.0.0
- 8.4
Configuration 4
- 9.0
No data.
Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8
n/a
Fixed · RHSA-2018:2939
Red Hat Enterprise Linux 8
springframework
Not affected
Red Hat Fuse 7
spring
Not affected
Red Hat JBoss A-MQ 6
spring
Not affected
Red Hat JBoss BRMS 5
spring
Not affected
Red Hat JBoss Data Virtualization 6
spring
Not affected
Red Hat JBoss Enterprise Application Platform 5
jbossweb
Not affected
Red Hat JBoss Enterprise Application Platform 6
jbossweb
Not affected
Red Hat JBoss Enterprise Application Platform 7
undertow
Not affected
Red Hat JBoss Enterprise Web Server 2
tomcat
Not affected
Red Hat JBoss Fuse 6
spring
Affected
Red Hat JBoss Fuse Integration Service 2
spring
Affected
Red Hat JBoss Fuse Service Works 6
spring
Not affected
Red Hat JBoss Portal 6
spring
Not affected
Red Hat JBoss SOA Platform 5
spring
Not affected
Red Hat JBoss Web Server 3
tomcat
Not affected
Red Hat Mobile Application Platform 4
spring
Not affected
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Not affected
Red Hat OpenStack Platform 11 (Ocata)
opendaylight
Not affected
Red Hat OpenStack Platform 12 (Pike)
opendaylight
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Not affected
Red Hat Storage 3
rhevm-dependencies
Not affected
Red Hat Virtualization 4
rhevm-dependencies
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8 | n/a | Fixed | RHSA-2018:2939 |
| Red Hat Enterprise Linux 8 | springframework | Not affected | n/a |
| Red Hat Fuse 7 | spring | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | spring | Not affected | n/a |
| Red Hat JBoss BRMS 5 | spring | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | spring | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | jbossweb | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | undertow | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | tomcat | Not affected | n/a |
| Red Hat JBoss Fuse 6 | spring | Affected | n/a |
| Red Hat JBoss Fuse Integration Service 2 | spring | Affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | spring | Not affected | n/a |
| Red Hat JBoss Portal 6 | spring | Not affected | n/a |
| Red Hat JBoss SOA Platform 5 | spring | Not affected | n/a |
| Red Hat JBoss Web Server 3 | tomcat | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | spring | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 12 (Pike) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Not affected | n/a |
| Red Hat Storage 3 | rhevm-dependencies | Not affected | n/a |
| Red Hat Virtualization 4 | rhevm-dependencies | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
No Red Hat products are directly affected by this flaw; the products that package some parts of the Spring Framework either do not ship the affected messaging component, or use an older version that is not affected. Fuse 6.3 and Fuse Integration Services 2.0 are both not directly affected by the flaw, but both point to the affected versions in their respective Camel-Springboot Maven repository BOMs. Fixes for those repository links will be addressed in advisories via regular patch cycle; customers using Spring stomp messaging from these Maven repositories are advised to update to the new BOMs when available.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (32 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 77.48% (0.77476) | 99.55th | v5 (v2026.06.15) |
| Jun 15, 2026 | 77.24% (0.77245) | 99.49th | v5 (v2026.06.15) |
| Nov 21, 2025 | 89.35% (0.89353) | 99.51th | v4 (v2025.03.14) |
| Nov 18, 2025 | 83.30% (0.83298) | 99.34th | v4 (v2025.03.14) |
| Jul 25, 2025 | 88.67% (0.88672) | 99.47th | v4 (v2025.03.14) |
| Mar 17, 2025 | 89.81% (0.89812) | 99.55th | v4 (v2025.03.14) |
| Dec 17, 2024 | 85.63% (0.85625) | 98.78th | v3 (v2023.03.01) |
| Nov 7, 2024 | 76.79% (0.76786) | 98.28th | v3 (v2023.03.01) |
| Sep 30, 2024 | 79.09% (0.79095) | 98.32th | v3 (v2023.03.01) |
| Aug 20, 2024 | 76.38% (0.76380) | 98.24th | v3 (v2023.03.01) |
| Jul 9, 2024 | 78.03% (0.78025) | 98.26th | v3 (v2023.03.01) |
| May 31, 2024 | 79.29% (0.79286) | 98.28th | v3 (v2023.03.01) |
| Mar 15, 2024 | 84.81% (0.84814) | 98.42th | v3 (v2023.03.01) |
| Feb 13, 2024 | 83.41% (0.83413) | 98.33th | v3 (v2023.03.01) |
| Nov 8, 2023 | 85.96% (0.85962) | 98.24th | v3 (v2023.03.01) |
| Oct 31, 2023 | 90.42% (0.90425) | 98.47th | v3 (v2023.03.01) |
| Oct 7, 2023 | 91.52% (0.91519) | 98.55th | v3 (v2023.03.01) |
| Aug 28, 2023 | 91.77% (0.91774) | 98.52th | v3 (v2023.03.01) |
| Jul 16, 2023 | 91.16% (0.91163) | 98.42th | v3 (v2023.03.01) |
| Jul 8, 2023 | 94.04% (0.94038) | 98.76th | v3 (v2023.03.01) |
| May 8, 2023 | 86.20% (0.86203) | 98.04th | v3 (v2023.03.01) |
| Mar 31, 2023 | 90.27% (0.90271) | 98.21th | v3 (v2023.03.01) |
| Mar 7, 2023 | 91.59% (0.91588) | 98.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 67.67% (0.67675) | 99.10th | v2 (v2022.01.01) |
| Jan 1, 2023 | 67.67% (0.67675) | 99.08th | v2 (v2022.01.01) |
| Feb 4, 2022 | 70.01% (0.70009) | 98.99th | v2 (v2022.01.01) |
| Feb 3, 2022 | 27.60% (0.27604) | 96.28th | v1 |
| Jan 6, 2022 | 27.60% (0.27604) | 96.24th | v1 |
| Oct 21, 2021 | 27.60% (0.27604) | 98.38th | v1 |
| Sep 1, 2021 | 26.40% (0.26401) | 98.31th | v1 |
| Apr 27, 2021 | 26.40% (0.26401) | 0.00th | v1 |
| Apr 14, 2021 | 25.16% (0.25157) | 0.00th | v1 |
References (29)
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.securityfocus.com/bid/103696 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2939 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1270 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1564405 Issue Tracking
- https://github.com/advisories/GHSA-p5hg-3xm3-gcjg Advisory
- https://github.com/spring-projects/spring-framework/commit/0009806debb578e884f6dc98bd1f2dc668020021
- https://github.com/spring-projects/spring-framework/commit/e0de9126ed8cf25cf141d3e66420da94e350708a
- https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1270
- https://pivotal.io/security/cve-2018-1270 x_refsource_CONFIRMVendor Advisory
- https://web.archive.org/web/20200227125035/https://www.securityfocus.com/bid/103696
- https://www.cve.org/CVERecord?id=CVE-2018-1270
- https://www.exploit-db.com/exploits/44796 exploitx_refsource_EXPLOIT-DBBroken LinkThird Party AdvisoryVDB Entry
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html x_refsource_CONFIRMPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.