CyberSec.Space Logo
Back to CVE Browser

CVE-2017-8046

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0810%
EPSS Percentile20.48th
PublishedJan 4, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

Affected Platforms (CPE)

πŸ“¦
Vmware

Spring Boot

< 1.5.9
πŸ“¦
Vmware

Spring Boot

= 2.0.0
πŸ“¦
Vmware

Spring Boot

= 2.0.0
πŸ“¦
Vmware

Spring Boot

= 2.0.0
πŸ“¦
Vmware

Spring Boot

= 2.0.0
πŸ“¦
Vmware

Spring Boot

= 2.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

< 2.6.9
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0
πŸ“¦
Pivotal Software

Spring Data Rest

= 3.0.0

References & Advisories

Related Vulnerabilities