CVE-2018-1259 is a property binder vulnerability affecting Spring Data Commons versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, when used with XMLBeam 1.4.14 or earlier. This flaw, categorized as CWE-611, allows an unauthenticated remote attacker to access arbitrary files on the system by supplying specially crafted request parameters due to improper restriction of XML external entity references. With a CVSS v3 score of 7.5 (HIGH), it presents a significant risk with low attack complexity and no user interaction required, leading to high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.13, <= 1.13.11CPE matchmatch criteria | cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:* | ||
>= 2.0, <= 2.0.6CPE matchmatch criteria | cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:* | ||
>= 3.0, <= 3.0.6CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_data_rest:*:*:*:*:*:*:*:* | ||
> 2.6, <= 2.6.11CPE matchmatch criteria | cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:* | ||
<= 1.4.14CPE matchmatch criteria | cpe:2.3:a:xmlbeam:xmlbeam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Oct 17, 2018spring-data-commons: XXE with Spring Data’s XMLBeam integration
May 9, 2018