Back

CVE-2018-1273

CRITICAL CISA KEV

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Published: Apr 11, 2018 Modified: Jun 26, 2026
CWE-94

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (11)

Vendor Product Version
broadcom spring_data_commons *
broadcom spring_data_commons * ≥ 1.13.0
broadcom spring_data_commons * ≥ 2.0.0
pivotal_software spring_data_rest * ≥ 3.0.0
vmware spring_data_rest *
vmware spring_data_rest * ≥ 2.6.0
apache ignite * ≥ 1.0.1
apache ignite 1.0.0
apache ignite 1.0.0
oracle financial_services_crime_and_compliance_management_studio 8.0.8.2.0
oracle financial_services_crime_and_compliance_management_studio 8.0.8.3.0

GitHub Security Advisory GHSA-4fq3-mr56-cg6r

Spring Data Commons remote code injection vulnerability

maven org.springframework.data:spring-data-commons >= 1.13.0, < 1.13.11 Fixed: 1.13.11
maven org.springframework.data:spring-data-commons >= 2.0.0, < 2.0.6 Fixed: 2.0.6

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 95.65%

Top 0% most likely to be exploited

Threat Score 97.9 / 100

CISA Known Exploited

Date Added: 2022-03-25
Due Date: 2022-04-15
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub