← Back to browse · API

CVE-2018-1273

Severity
CRITICAL
CVSS
9.8
EPSS
0.95649
Risk score
58.48
CISA KEV
Yes
PoC
No
Published
2018-04-11
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2018-0500, GHSA-4FQ3-MR56-CG6R
Products
VMware Tanzu:Spring Data Commons, VMware:Spring Framework Versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions
Sources
cisa.gov CVE-2018-1273
euvd EUVD-2018-0500

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

References