Loading
Generated remediation guidance and an executive summary. No account required.
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
Use CWE-770, Pivotal Software vendor hub and Spring Data Commons product page to widen CVE-2018-1274 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-1273 and CVE-2018-1259 for nearby disclosures in the same product family.