Back

CRITICAL KEV Used in ransomware campaigns

spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests

Published Apr 11, 2018 ·Due Apr 15, 2022

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Apr 11, 2018
Updated Aug 26, 2026
Reserved Dec 6, 2017
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Aug 26, 2026
Red Hat
Severity Critical
Public date Mar 27, 2018
GHSA-4FQ3-MR56-CG6R