spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of service
Published Apr 18, 2018
7.5
HIGHCVSS 3.1
EPSS 1.93%
Description
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Affected products
-
- Version Versions 1.13 to 1.13.10, 2.0 to 2.0.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring by Pivotal | Spring Framework | n/a |
|
Configuration 1
- < 1.13.11
- ≥ 2.0.0 · < 2.0.6
Configuration 2
- ≥ 3.0 · ≤ 3.0.5
- ≥ 2.6 · ≤ 2.6.10
No data.
Red Hat Fuse 7
spring-data-commons
Affected
Red Hat JBoss Fuse 6
spring-data-commons
Not affected
Red Hat JBoss Fuse Integration Service 2
spring-data-commons
Not affected
Red Hat Mobile Application Platform 4
spring-data-commons
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | spring-data-commons | Affected | n/a |
| Red Hat JBoss Fuse 6 | spring-data-commons | Not affected | n/a |
| Red Hat JBoss Fuse Integration Service 2 | spring-data-commons | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | spring-data-commons | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- http://www.securityfocus.com/bid/103769 vdb-entryx_refsource_BIDBroken Link
- https://access.redhat.com/security/cve/CVE-2018-1274 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1565926 Issue Tracking
- https://github.com/advisories/GHSA-5q8m-mqmx-pxp9 Advisory
- https://github.com/spring-projects/spring-data-commons/commit/371f6590c509c72f8e600f3d05e110941607fba
- https://github.com/spring-projects/spring-data-commons/commit/3d8576fe4e4e71c23b9e6796b32fd56e51182ee
- https://nvd.nist.gov/vuln/detail/CVE-2018-1274
- https://pivotal.io/security/cve-2018-1274 x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1274
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/103769 | vdb-entryx_refsource_BIDBroken Link | |
| https://access.redhat.com/security/cve/CVE-2018-1274 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1565926 | Issue Tracking | |
| https://github.com/advisories/GHSA-5q8m-mqmx-pxp9 | Advisory | |
| https://github.com/spring-projects/spring-data-commons/commit/371f6590c509c72f8e600f3d05e110941607fba | ||
| https://github.com/spring-projects/spring-data-commons/commit/3d8576fe4e4e71c23b9e6796b32fd56e51182ee | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-1274 | ||
| https://pivotal.io/security/cve-2018-1274 | x_refsource_CONFIRMVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-1274 | ||
| https://www.oracle.com/security-alerts/cpujul2022.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.