CVE-2018-1274

HIGH

Pivotal Software Spring Data Commons < 1.13.11 - Resource Allocation Without Limits

Title source: rule

Description

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

Exploits (1)

nomisec STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2018-1274-spring-data-commons-vulnerable

Scores

CVSS v3 7.5
EPSS 0.0097
EPSS Percentile 76.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-770
Status published

Affected Products (3)

pivotal_software/spring_data_commons < 1.13.11
pivotal_software/spring_data_rest < 2.6.10
org.springframework.data/spring-data-commons < 1.13.11Maven

Timeline

Published Apr 18, 2018
Tracked Since Feb 18, 2026