CVE-2018-1273

CRITICAL KEV RANSOMWARE NUCLEI

Pivotal Software Spring Data Commons < 1.12.10 - Code Injection

Title source: rule

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Exploits (9)

nomisec WORKING POC 58 stars
by jas502n · remote
https://github.com/jas502n/cve-2018-1273
nomisec WORKING POC 24 stars
by wearearima · poc
https://github.com/wearearima/poc-cve-2018-1273
nomisec WORKING POC 10 stars
by knqyf263 · remote
https://github.com/knqyf263/CVE-2018-1273
github WORKING POC 5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/spring-CVE-2018-1273
nomisec WORKING POC 2 stars
by webr0ck · poc
https://github.com/webr0ck/poc-cve-2018-1273
nomisec WORKING POC
by hdgokani · remote
https://github.com/hdgokani/CVE-2018-1273
nomisec STUB
by cved-sources · poc
https://github.com/cved-sources/cve-2018-1273
nomisec STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2018-1273-spring-data-commons-vulnerable

Nuclei Templates (1)

Spring Data Commons - Remote Code Execution
CRITICALby dwisiswant0

Scores

CVSS v3 9.8
EPSS 0.9429
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-03-25
VulnCheck KEV 2019-01-08
InTheWild.io 2019-03-13
ENISA EUVD EUVD-2018-0500
Ransomware Use Confirmed

Classification

CWE
CWE-94
Status published

Affected Products (8)

pivotal_software/spring_data_commons < 1.12.10
pivotal_software/spring_data_rest < 2.5.10
apache/ignite < 2.5.0
apache/ignite
apache/ignite
oracle/financial_services_crime_and_compliance_management_studio
oracle/financial_services_crime_and_compliance_management_studio
org.springframework.data/spring-data-commons < 1.13.11Maven

Timeline

Published Apr 11, 2018
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026