Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
History

Mon, 15 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom spring Data Commons
CPEs cpe:2.3:a:pivotal_software:spring_data_commons:*:*:*:*:*:*:*:* cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*
Vendors & Products Pivotal Software spring Data Commons
Broadcom
Broadcom spring Data Commons

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T16:33:36.641Z

Reserved: 2017-12-06T00:00:00.000Z

Link: CVE-2018-1259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-11T20:29:00.307

Modified: 2026-06-17T01:50:50.290

Link: CVE-2018-1259

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-05-09T00:00:00Z

Links: CVE-2018-1259 - Bugzilla

cve-icon OpenCVE Enrichment

No data.