CVE-2018-1196
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the "run_user" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible.
Spring Boot soporta un script de inicio embebido que puede emplearse para ejecuta fácilmente la aplicación como servicio de linux systemd o init.d. El script incluido con Spring Boot 1.5.9 y anteriores y 2.0.0.M1 hasta 2.0.0.M7 es susceptible a un ataque symlink que permite que "run_user" sobrescriba y se haga dueño de cualquier archivo en el mismo sistema. Para instigar el ataque, la aplicación debe estar instalada como servicio y "run_user" requiere acceso shell al servidor. Las aplicaciones Spring Boot que no estén instaladas como servicio o que no estén usando el script de inicio embebido no son susceptibles.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-03-19 CVE Published
- 2024-01-27 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pivotal.io/security/cve-2018-1196 | 2022-04-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | <= 1.5.9 Search vendor "Vmware" for product "Spring Boot" and version " <= 1.5.9" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | 2.0.0 Search vendor "Vmware" for product "Spring Boot" and version "2.0.0" | milestone1 |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | 2.0.0 Search vendor "Vmware" for product "Spring Boot" and version "2.0.0" | milestone2 |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | 2.0.0 Search vendor "Vmware" for product "Spring Boot" and version "2.0.0" | milestone3 |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | 2.0.0 Search vendor "Vmware" for product "Spring Boot" and version "2.0.0" | milestone4 |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | 2.0.0 Search vendor "Vmware" for product "Spring Boot" and version "2.0.0" | milestone5 |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | 2.0.0 Search vendor "Vmware" for product "Spring Boot" and version "2.0.0" | milestone6 |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Boot Search vendor "Vmware" for product "Spring Boot" | 2.0.0 Search vendor "Vmware" for product "Spring Boot" and version "2.0.0" | milestone7 |
Affected
|