CRITICAL9.8
GHSA-4fq3-mr56-cg6r
Spring Data Commons remote code injection vulnerability
Quick fix
GHSA-4fq3-mr56-cg6r — org.springframework.data:spring-data-commons: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.13.11</version> for org.springframework.data:spring-data-commonsDetails
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding that can lead to a remote code execution attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.springframework.data:spring-data-commons
Introduced in:
1.13.0Fixed in: 1.13.11Fix
# pom.xml: bump <version>1.13.11</version> for org.springframework.data:spring-data-commonsMaven/org.springframework.data:spring-data-commons
Introduced in:
2.0.0Fixed in: 2.0.6Fix
# pom.xml: bump <version>2.0.6</version> for org.springframework.data:spring-data-commonsReferences
- https://nvd.nist.gov/vuln/detail/CVE-2018-1273[ADVISORY]
- https://github.com/spring-projects/spring-data-commons/issues/1721[WEB]
- https://github.com/spring-projects/spring-data-commons/commit/ae1dd2741ce06d44a0966ecbd6f47beabde2b653[WEB]
- https://github.com/spring-projects/spring-data-commons/commit/b1a20ae1e82a63f99b3afc6f2aaedb3bf4dc432a[WEB]
- https://github.com/advisories/GHSA-4fq3-mr56-cg6r[ADVISORY]
- https://github.com/spring-projects/spring-data-commons[PACKAGE]
- https://pivotal.io/security/cve-2018-1273[WEB]
- https://www.oracle.com/security-alerts/cpujul2022.html[WEB]
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E[WEB]