CVE-2018-1274
7.5 HIGHSpring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability...
Published: 2018-04-18 · Last updated: 2026-06-15
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-770
Affected products
| Vendor | Product |
|---|---|
| broadcom | spring_data_commons, spring_data_rest |
| pivotal_software | spring_data_commons, spring_data_rest |
Description
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2018-1274
- [Other]http://www.securityfocus.com/bid/103769
- [Vendor advisory]https://pivotal.io/security/cve-2018-1274
- [Other]https://www.oracle.com/security-alerts/cpujul2022.html
- [Other]http://www.securityfocus.com/bid/103769
- [Vendor advisory]https://pivotal.io/security/cve-2018-1274
- [Other]https://www.oracle.com/security-alerts/cpujul2022.html
Related CVEs
Same vendor
- CVE-2026-41721 — Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled i... (5.9 MEDIUM)
- CVE-2026-41716 — Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhau... (7.5 HIGH)
- CVE-2026-41711 — Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when par... (5.9 MEDIUM)
- CVE-2026-41695 — Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property pat... (7.5 HIGH)
- CVE-2026-44839 — RabbitMQ is a messaging and streaming broker (4.8 MEDIUM)
Same CWE
- CVE-2026-48854 — Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BE...
- CVE-2026-48853 — Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unau...
- CVE-2026-8683 — Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App w... (6.5 MEDIUM)
- CVE-2026-53522 — Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (6.5 MEDIUM)
- CVE-2026-50560 — Netty is a network application framework for development of protocol servers and clients (5.3 MEDIUM)