VDB
Sign up
CRITICAL9.8

GHSA-4fq3-mr56-cg6r

Spring Data Commons remote code injection vulnerability

Quick fix

GHSA-4fq3-mr56-cg6r — org.springframework.data:spring-data-commons: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.13.11</version> for org.springframework.data:spring-data-commons

Details

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding that can lead to a remote code execution attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework.data:spring-data-commons
Introduced in: 1.13.0Fixed in: 1.13.11
Fix# pom.xml: bump <version>1.13.11</version> for org.springframework.data:spring-data-commons
Maven/org.springframework.data:spring-data-commons
Introduced in: 2.0.0Fixed in: 2.0.6
Fix# pom.xml: bump <version>2.0.6</version> for org.springframework.data:spring-data-commons

References