{"id":"CVE-2018-1273","details":"Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.","aliases":["GHSA-4fq3-mr56-cg6r"],"modified":"2026-07-08T05:50:57.155880589Z","published":"2018-04-11T13:29:00.290Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"3.0.0"},{"last_affected":"3.0.5"}],"cpes":["cpe:2.3:a:pivotal_software:spring_data_rest:*:*:*:*:*:*:*:*"],"vendor_product":"pivotal_software:spring_data_rest","source":"CPE_RANGE"},{"extracted_events":[{"introduced":"8.0.8.2.0"},{"last_affected":"8.0.8.2.0"},{"introduced":"8.0.8.3.0"},{"last_affected":"8.0.8.3.0"}],"cpes":["cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:financial_services_crime_and_compliance_management_studio","source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1273"},{"type":"ADVISORY","url":"http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E"},{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2018-1273"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/ignite","events":[{"introduced":"fceebf26559068eac36b7395a7c6d51229c33469"},{"last_affected":"86e110c750a340dc9be2d396415f0b80d7ed8813"},{"introduced":"5fc2cd053467e65872f796e11e3edd2e6017d80d"},{"last_affected":"f54fc36cc29533ea0ea49eacc345b7f769491bf8"}],"database_specific":{"extracted_events":[{"introduced":"1.0.1"},{"last_affected":"2.5.0"},{"introduced":"1.0.0-NA"},{"last_affected":"1.0.0-NA"},{"introduced":"1.0.0-rc3"},{"last_affected":"1.0.0-rc3"}],"cpe":["cpe:2.3:a:apache:ignite:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:ignite:1.0.0:-:*:*:*:*:*:*","cpe:2.3:a:apache:ignite:1.0.0:rc3:*:*:*:*:*:*"],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.0.0-NA","1.0.0-rc3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1273.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-data-commons","events":[{"introduced":"0"},{"last_affected":"f386cd6e47d018c2f7640869bf5595797e3f74c0"},{"introduced":"d5cad6c27f765587a3976620324153352058a4a7"},{"last_affected":"8ddb7cefe1fb0ba075dbbdc7035ab7e2a5c75c19"},{"introduced":"dc8583795871a09d78a15b075935a6cada57d597"},{"last_affected":"70ac316b400937d7e1dff71c1605a4205fc818bd"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.12.10"},{"introduced":"1.13.0"},{"last_affected":"1.13.10"},{"introduced":"2.0.0"},{"last_affected":"2.0.5"}],"cpe":"cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*","source":"CPE_RANGE"}}],"versions":["2.0.5.RELEASE","2.0.4.RELEASE","2.0.3.RELEASE","1.13.10.RELEASE","2.0.2.RELEASE","1.13.9.RELEASE","2.0.1.RELEASE","1.13.8.RELEASE","2.0.0.RELEASE","1.13.7.RELEASE","1.13.6.RELEASE","1.13.5.RELEASE","1.13.4.RELEASE","1.12.10.RELEASE","1.13.3.RELEASE","1.12.9.RELEASE","1.13.2.RELEASE","1.12.8.RELEASE","1.13.1.RELEASE","1.12.7.RELEASE","1.13.0.RELEASE","1.12.6.RELEASE","1.12.5.RELEASE","1.12.4.RELEASE","1.12.3.RELEASE","1.12.2.RELEASE","1.12.1.RELEASE","1.12.0.RELEASE","1.12.0.RC1","1.12.0.M1","1.11.0.RELEASE","1.11.0.RC1","1.11.0.M1","1.10.0.RELEASE","1.10.0.RC1","1.10.0.M1","1.9.0.RELEASE","1.9.0.RC1","1.9.0.M1","1.8.0.RELEASE","1.8.0.RC1","1.8.0.M1","1.7.0.RELEASE","1.7.0.RC1","1.7.0.M1","1.6.0.RELEASE","1.6.0.RC1","1.6.0.M1","1.5.0.RELEASE","1.4.0.RELEASE","1.4.0.RC1","1.4.0.M1","1.3.0.RELEASE","1.3.0.RC2","1.3.0.RC1","1.3.0.M1","1.2.0.RELEASE","1.2.0.RC1","1.2.0.M2","1.2.0.M1","1.1.0.RELEASE","1.1.0.RC1","1.1.0.M2","1.1.0.M1","1.0.0.RELEASE","1.0.0.RC1","1.0.0.M6","1.0.0.M5","1.0.0.M4","1.0.0.M3","1.0.0.M2","1.0.0.M1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1273.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-data-rest","events":[{"introduced":"0"},{"last_affected":"f56485d92daceaca47e050d15f0088265852d7d8"},{"introduced":"93a2c589c5efc9e550b15103ba707c2b60f8725c"},{"last_affected":"f916233f410b9d27e2ddb23de4c9ff1e29af29b5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.5.10"},{"introduced":"2.6.0"},{"last_affected":"2.6.10"}],"cpe":"cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*","source":"CPE_RANGE"}}],"versions":["2.6.10.RELEASE","2.6.9.RELEASE","2.6.8.RELEASE","2.6.7.RELEASE","2.6.6.RELEASE","2.6.5.RELEASE","2.6.4.RELEASE","2.5.10.RELEASE","2.6.3.RELEASE","2.5.9.RELEASE","2.6.2.RELEASE","2.5.8.RELEASE","2.6.1.RELEASE","2.5.7.RELEASE","2.6.0.RELEASE","2.5.6.RELEASE","2.5.5.RELEASE","2.5.4.RELEASE","2.5.3.RELEASE","2.5.2.RELEASE","2.5.1.RELEASE","2.5.0.RELEASE","2.5.0.RC1","2.5.0.M1","2.4.0.RELEASE","2.4.0.RC1","2.4.0.M1","2.3.0.RELEASE","2.3.0.RC1","2.3.0.M1","2.2.0.RELEASE","2.2.0.RC1","2.2.0.M1","2.1.0.RELEASE","2.1.0.RC1","2.1.0.M1","2.0.0.RELEASE","2.0.0.RC1","2.0.0.M1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1273.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}