logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2018-1273

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2018-1273

Description:
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Last updated date:
03/14/2025

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
03/13/2019
Reference url to background

https://securityaffairs.co/wordpress/82327/malware/psminer-modular-cryptominer.html

Type:
exploitation
Confidence:
HIGH
Date of publishing:
03/25/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/13/2018
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/17/2018
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/05/2018
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/29/2019
Reference url to background

https://github.com/jas502n/cve-2018-1273

Type:
exploit
Confidence:
HIGH
Date of publishing:
06/26/2020
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy