Generated remediation guidance and an executive summary. No account required.
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Use CWE-611, Pivotal Software vendor hub and Spring Data Commons product page to widen CVE-2018-1259 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-1273 and CVE-2018-1274 for nearby disclosures in the same product family.