PT-2018-2614 · Spring · Spring Framework

CVE-2018-1270

·

Publicado

2018-04-05

·

Atualizado

2026-03-10

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring Framework versions 4.3 prior to 4.3.15 and versions 5.0 prior to 5.0.5
Description The issue is caused by errors in handling STOMP messages in the spring-messaging module of the Spring Framework. A malicious user can craft a message to the broker that can lead to a remote code execution attack. This can be done by exploiting the simple, in-memory STOMP broker exposed through WebSocket endpoints.
Recommendations For versions 4.3 prior to 4.3.15, update to version 4.3.15 or later to resolve the issue. For versions 5.0 prior to 5.0.5, update to version 5.0.5 or later to resolve the issue. As a temporary workaround, consider disabling the STOMP broker over WebSocket endpoints until a patch is available. Restrict access to the spring-messaging module to minimize the risk of exploitation. Avoid using the STOMP protocol in the affected API endpoints until the issue is resolved.

Exploit

Correção

RCE

Code Injection

Improperly Implemented Security Check for Standard

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01223
CVE-2018-1270
DLA-2635-1
GHSA-P5HG-3XM3-GCJG

Produtos afetados

Spring Framework