Review reviewHigh

CVE-2018-1274

Spring by Pivotal Spring Framework, spring data commons, spring data rest

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

CVSS
7.5
EPSS
1.97%
78.5% percentile
CISA KEV
Not listed
Published
2018.04.19
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.97%
Technical severityCVSS 7.5

Vulnerability overview

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

Affected product and versions

Product
Spring by Pivotal Spring Framework, spring data commons, spring data rest
Affected versions
Versions 1.13 to 1.13.10, 2.0 to 2.0.5, < 1.13.11, >= 2.0.0 < 2.0.6, >= 3.0 <= 3.0.5, >= 2.6 <= 2.6.10
Fixed versions
1.13.11, 2.0.6

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Spring by Pivotal Spring Framework, spring data commons, spring data rest and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-770