spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
Published Apr 11, 2018 ·Due Apr 15, 2022
9.8
CRITICALCVSS 3.1
EPSS 96.96%
Description
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Affected products
-
- Version Versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring by Pivotal | Spring Framework | n/a |
|
Configuration 1
- ≤ 1.12.10
- ≥ 1.13.0 · ≤ 1.13.10
- ≥ 2.0.0 · ≤ 2.0.5
Configuration 2
- ≥ 3.0.0 · ≤ 3.0.5
- ≤ 2.5.10
- ≥ 2.6.0 · ≤ 2.6.10
Configuration 3
Configuration 4
- 8.0.8.2.0
- 8.0.8.3.0
No data.
Red Hat Fuse 7
spring-data-commons
Affected
Red Hat JBoss Fuse 6
spring-data-commons
Not affected
Red Hat JBoss Fuse Integration Service 2
spring-data-commons
Not affected
Red Hat Mobile Application Platform 4
spring-data-commons
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | spring-data-commons | Affected | n/a |
| Red Hat JBoss Fuse 6 | spring-data-commons | Not affected | n/a |
| Red Hat JBoss Fuse Integration Service 2 | spring-data-commons | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | spring-data-commons | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
Mar 25, 2022
Patch Due
Apr 15, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 96.96% (0.96956) | 99.89th | v5 (v2026.06.15) |
| Aug 29, 2026 | 97.00% (0.97002) | 99.89th | v5 (v2026.06.15) |
| Jun 15, 2026 | 95.65% (0.95649) | 99.86th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.34% (0.94336) | 99.95th | v4 (v2025.03.14) |
| Mar 15, 2025 | 96.13% (0.96133) | 99.66th | v3 (v2023.03.01) |
| Jul 17, 2024 | 97.24% (0.97241) | 99.86th | v3 (v2023.03.01) |
| Jul 14, 2024 | 97.45% (0.97453) | 99.96th | v3 (v2023.03.01) |
| Mar 20, 2024 | 97.47% (0.97466) | 99.96th | v3 (v2023.03.01) |
| Feb 18, 2024 | 97.47% (0.97474) | 99.96th | v3 (v2023.03.01) |
| Jan 25, 2024 | 97.52% (0.97515) | 99.98th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.50% (0.97498) | 99.96th | v3 (v2023.03.01) |
| May 8, 2023 | 97.53% (0.97528) | 99.98th | v3 (v2023.03.01) |
| Apr 5, 2023 | 97.50% (0.97497) | 99.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.51% (0.97513) | 99.97th | v3 (v2023.03.01) |
| Mar 6, 2023 | 85.04% (0.85039) | 99.67th | v2 (v2022.01.01) |
| Jan 6, 2023 | 85.04% (0.85039) | 99.66th | v2 (v2022.01.01) |
| Jul 23, 2022 | 86.37% (0.86372) | 99.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 86.60% (0.86603) | 99.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 15.83% (0.15833) | 90.14th | v1 |
| Jan 6, 2022 | 15.83% (0.15833) | 90.02th | v1 |
| Sep 1, 2021 | 15.83% (0.15833) | 97.31th | v1 |
| Apr 14, 2021 | 15.83% (0.15833) | 0.00th | v1 |
References (13)
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1273 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1565923 Issue Tracking
- https://github.com/advisories/GHSA-4fq3-mr56-cg6r Advisory
- https://github.com/spring-projects/spring-data-commons/commit/ae1dd2741ce06d44a0966ecbd6f47beabde2b653
- https://github.com/spring-projects/spring-data-commons/commit/b1a20ae1e82a63f99b3afc6f2aaedb3bf4dc432a
- https://github.com/spring-projects/spring-data-commons/issues/1721
- https://nvd.nist.gov/vuln/detail/CVE-2018-1273
- https://pivotal.io/security/cve-2018-1273 x_refsource_CONFIRMVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1273 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2018-1273
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.