CVE-2018-1273
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
CISA KEV
- Vendor
- VMware Tanzu
- Product
- Spring Data Commons
- Due date
- 2022-04-15
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2018-1273
Exploits
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.springframework.data:spring-data-commons | >=1.13.0,<1.13.11 | 1.13.11 |
| Maven | org.springframework.data:spring-data-commons | >=2.0.0,<2.0.6 | 2.0.6 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-1273
- https://github.com/spring-projects/spring-data-commons/issues/1721
- https://github.com/spring-projects/spring-data-commons/commit/ae1dd2741ce06d44a0966ecbd6f47beabde2b653
- https://github.com/spring-projects/spring-data-commons/commit/b1a20ae1e82a63f99b3afc6f2aaedb3bf4dc432a
- https://github.com/advisories/GHSA-4fq3-mr56-cg6r
- https://github.com/spring-projects/spring-data-commons
- https://pivotal.io/security/cve-2018-1273
- https://www.oracle.com/security-alerts/cpujul2022.html
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
Verify integrity in audit chain (admin only). AS-IS.