Priority reviewCritical

CVE-2017-8046

Pivotal Pivotal Spring Data REST and Spring Boot, spring boot, spring data rest

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

CVSS
9.8
EPSS
74.4%
99.4% percentile
CISA KEV
Not listed
Published
2018.01.04
PRIORITY ASSESSMENT

Priority review

FIRST EPSS indicates an elevated probability of exploitation.

Known exploitationNot established by KEV
Exploit probability74.4%
Technical severityCVSS 9.8

Vulnerability overview

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

Affected product and versions

Product
Pivotal Pivotal Spring Data REST and Spring Boot, spring boot, spring data rest
Affected versions
Pivotal Spring Data REST versions prior to 2.6.9 (Ingalls SR9), 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6, < 1.5.9, 2.0.0, 3.0.0, < 2.6.9
Fixed versions
1.5.9, 2.6.9

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Pivotal Pivotal Spring Data REST and Spring Boot, spring boot, spring data rest and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-20
CVE-2017-8046 — Pivotal Pivotal Spring Data REST and Spring Boot, spring boot, spring data rest | SECUFOCUS NOW