CVE-2018-1258 describes an authorization bypass vulnerability in Spring Framework 5.0.5 when used with any version of Spring Security, affecting products from vendors like NetApp, Oracle, and VMware. This high-severity flaw (CVSS 8.8) allows a low-privileged attacker to gain unauthorized access to restricted methods over the network with low attack complexity, potentially leading to significant impacts on confidentiality, integrity, and availability. While no public exploits or Metasploit modules are available, and there's minimal community discussion or media coverage, its high CVSS score warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security:*:*:*:*:*:*:*:* | ||
5.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:5.0.5:*:*:*:*:*:*:* | ||
9.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:* | ||
9.3.4CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.4:*:*:*:*:*:*:* | ||
9.3.5CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.