CVE-2018-1274
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Spring Data Commons, en versiones anteriores a las comprendidas entre la 1.13 y la 1.13.10 y entre la 2.0 y la 2.0.5 y versiones antiguas no soportadas, contiene una vulnerabilidad property path parser provocada por la asignación de recursos ilimitada. Un usuario (o atacante) remoto no autenticado puede enviar peticiones contra los endpoints REST de Spring Data o a los endpoints empleando el análisis de ruta de propiedades, lo que puede provocar una denegación de servicio (consumo de CPU y de recursos).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-04-18 CVE Published
- 2023-10-19 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103769 | Third Party Advisory | |
https://www.oracle.com/security-alerts/cpujul2022.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pivotal.io/security/cve-2018-1274 | 2022-07-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Software Search vendor "Pivotal Software" | Spring Data Commons Search vendor "Pivotal Software" for product "Spring Data Commons" | >= 1.13 <= 1.13.10 Search vendor "Pivotal Software" for product "Spring Data Commons" and version " >= 1.13 <= 1.13.10" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Spring Data Commons Search vendor "Pivotal Software" for product "Spring Data Commons" | >= 2.0 <= 2.0.5 Search vendor "Pivotal Software" for product "Spring Data Commons" and version " >= 2.0 <= 2.0.5" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Spring Data Rest Search vendor "Pivotal Software" for product "Spring Data Rest" | >= 2.6 <= 2.6.10 Search vendor "Pivotal Software" for product "Spring Data Rest" and version " >= 2.6 <= 2.6.10" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Spring Data Rest Search vendor "Pivotal Software" for product "Spring Data Rest" | >= 3.0 <= 3.0.5 Search vendor "Pivotal Software" for product "Spring Data Rest" and version " >= 3.0 <= 3.0.5" | - |
Affected
|