7.5
CVE-2018-1274
- EPSS 0.97%
- Published 18.04.2018 16:29:00
- Last modified 12.09.2025 19:46:05
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Data is provided by the National Vulnerability Database (NVD)
Pivotal Software ≫ Spring Data Commons Version < 1.13.11
Pivotal Software ≫ Spring Data Commons Version >= 2.0.0 < 2.0.6
Pivotal Software ≫ Spring Data Rest Version >= 2.6 <= 2.6.10
Pivotal Software ≫ Spring Data Rest Version >= 3.0 <= 3.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.97% | 0.756 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.