7.5
CVE-2018-1274
- EPSS 0.97%
- Veröffentlicht 18.04.2018 16:29:00
- Zuletzt bearbeitet 12.09.2025 19:46:05
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pivotal Software ≫ Spring Data Commons Version < 1.13.11
Pivotal Software ≫ Spring Data Commons Version >= 2.0.0 < 2.0.6
Pivotal Software ≫ Spring Data Rest Version >= 2.6 <= 2.6.10
Pivotal Software ≫ Spring Data Rest Version >= 3.0 <= 3.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.97% | 0.756 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.