CVE-2018-1273 - VMware Tanzu Spring Data Commons
AI Vulnerability ContextSpring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat ca...
Overview
A source-backed snapshot of this vulnerability.
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2018-1273
- Vendor/project
- VMware Tanzu
- Product
- Spring Data Commons
- Vulnerability name
- VMware Tanzu Spring Data Commons Property Binder Vulnerability
- Date added
- 2022-03-25
- Due date
- 2022-04-15
- Known ransomware campaign use
- Known
- CVSS v3
- 9.8
Exploit context
What the vulnerability is about.
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
