CVE-2018-1274
HIGHPivotal Software Spring Data Commons < 1.13.11 - Resource Allocation Without Limits
Title source: ruleDescription
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Exploits (1)
nomisec
STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2018-1274-spring-data-commons-vulnerable
Scores
CVSS v3
7.5
EPSS
0.0097
EPSS Percentile
76.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-770
Status
published
Affected Products (3)
pivotal_software/spring_data_commons
< 1.13.11
pivotal_software/spring_data_rest
< 2.6.10
org.springframework.data/spring-data-commons
< 1.13.11Maven
Timeline
Published
Apr 18, 2018
Tracked Since
Feb 18, 2026