CVE-2017-8046 is a critical remote code execution vulnerability affecting Spring Data REST versions prior to 2.6.9 and 3.0.1, and Spring Boot versions prior to 1.5.9 and 2.0 M6. Attackers can exploit this by sending specially crafted JSON data within malicious PATCH requests. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary Java code, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, exploit code is publicly available via Nuclei templates and ExploitDB, and it has garnered significant community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.9CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:2.0.0:milestone1:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:2.0.0:milestone2:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:2.0.0:milestone3:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:2.0.0:milestone4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.