{"id":"CVE-2018-1196","details":"Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the \"run_user\" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the \"run_user\" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible.","aliases":["GHSA-xx65-cc7g-9pfp"],"modified":"2026-07-08T15:09:35.958553Z","published":"2018-03-19T18:29:00.387Z","references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2018-1196"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-boot","events":[{"introduced":"0"},{"last_affected":"1e8b9569d3a3900a0ed61712099823ad735b8078"},{"introduced":"a9503abb94b203a717527b81a94dc9d3cb4b1afa"},{"last_affected":"95df4859a54c63652a0b455b8d6c8133d4c0091a"}],"database_specific":{"cpe":["cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_boot:2.0.0:milestone1:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_boot:2.0.0:milestone2:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_boot:2.0.0:milestone3:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_boot:2.0.0:milestone4:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_boot:2.0.0:milestone5:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_boot:2.0.0:milestone6:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_boot:2.0.0:milestone7:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.5.9"},{"introduced":"2.0.0-milestone1"},{"last_affected":"2.0.0-milestone1"},{"introduced":"2.0.0-milestone2"},{"last_affected":"2.0.0-milestone2"},{"introduced":"2.0.0-milestone3"},{"last_affected":"2.0.0-milestone3"},{"introduced":"2.0.0-milestone4"},{"last_affected":"2.0.0-milestone4"},{"introduced":"2.0.0-milestone5"},{"last_affected":"2.0.0-milestone5"},{"introduced":"2.0.0-milestone6"},{"last_affected":"2.0.0-milestone6"},{"introduced":"2.0.0-milestone7"},{"last_affected":"2.0.0-milestone7"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.0.0-milestone1","2.0.0-milestone2","2.0.0-milestone3","2.0.0-milestone4","2.0.0-milestone5","2.0.0-milestone6","2.0.0-milestone7","v2.0.0.M7","v1.5.9.RELEASE","v1.0.0.RC4","v1.0.0.RC3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1196.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}