CVE-2018-1273

Executive Summary

Spring Data Commons versions 1.13.x, 2.0.x and older contain a property binder vulnerability that fails to neutralize special elements. An unauthenticated attacker can supply crafted request parameters to Spring Data REST or projection-based payloads, enabling remote code execution. The vulnerability is actively exploited (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2018-04-11T13:29:00.290 - Last Modified: 2026-08-26T05:18:03.100

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-03-25)

Original Description: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

"Most folks are about as happy as they make up their minds to be."

— Abraham Lincoln
Source: NVD