S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-1273 Scanner

CVE-2018-1273 scanner - Remote Code Execution (RCE) vulnerability in Spring Data Commons

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-1273
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Spring Frameworkby Spring by Pivotal
Versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions
Updated Aug 26, 2026View on NVD →
Detail

Spring Data Commons is an open-source project that aims to simplify the implementation of data access layers in Spring-based applications. It provides a consistent programming model for various data stores, including relational databases, NoSQL databases, and others. Spring Data Commons provides a set of abstractions on top of data access technologies, including query building, pagination, and auditing. Spring Data Commons version 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions have been found to have a vulnerability, CVE-2018-1273.

CVE-2018-1273 vulnerability in Spring Data Commons stems from the improper neutralization of specially crafted input. The vulnerability resides in Spring Data Commons' property binder, which fails to neutralize the input of certain parameters. This can allow unauthenticated remote attackers to exploit the vulnerability by sending a specially crafted request to the Spring Data REST-backed HTTP resources or using Spring Data's projection-based request payload binding. Upon successful exploitation, the attacker can execute remote code on the affected system.

When the CVE-2018-1273 vulnerability is exploited, attackers can take complete control of the affected system, execute arbitrary code, and access sensitive information. The remote code execution attack can lead to a complete compromise of the system, and the attacker can gain access to confidential data, alter or delete data, and install malware or other malicious software on the compromised system. The attackers can maintain persistence and continue to exploit the system even after the initial attack.

Thanks to the pro features of the s4e.io platform, businesses and organizations can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a comprehensive vulnerability assessment service that can identify vulnerabilities in digital assets, including applications, networks, and cloud environments. With the platform's rich set of features, businesses can monitor their entire digital asset inventory, generate reports, and receive timely alerts on critical issues. By leveraging the power of s4e.io, businesses can stay ahead of emerging security threats and protect their digital assets from attackers.

 

REFERENCES

Solution Advice

To protect against the CVE-2018-1273 vulnerability in Spring Data Commons, the following precautions can be taken:

  • Upgrade to the latest supported version of Spring Data Commons
  • Apply patches provided by the vendor if upgrading is not possible
  • Restrict access to the Spring Data REST endpoints to trusted parties only
  • Monitor network activity for suspicious requests targeting Spring Data REST endpoints
  • Implement ACLs and other access controls to limit unauthorized access to the system

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-1273 scanner - Remote Code Execution (RCE) vulnerability in Spring Data Commons | S4E