7.5

CVE-2018-1274

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Spring Data Commons Version < 1.13.11
Broadcom ≫ Spring Data Commons Version >= 2.0.0 < 2.0.6
Pivotal Software ≫ Spring Data Rest Version >= 3.0 <= 3.0.5
VMware ≫ Spring Data Rest Version >= 2.6 <= 2.6.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.97% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://www.oracle.com/security-alerts/cpujul2022.html
Third Party Advisory
http://www.securityfocus.com/bid/103769
Broken Link
https://pivotal.io/security/cve-2018-1274
Vendor Advisory