Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 22 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Thu, 31 Jul 2025 09:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-74 | 
Fri, 14 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | NVD-CWE-Other | 
Fri, 07 Feb 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | kev 
 
 | 
Wed, 14 Aug 2024 00:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: dell
Published: 2018-04-11T13:00:00.000Z
Updated: 2025-10-21T23:45:52.285Z
Reserved: 2017-12-06T00:00:00.000Z
Link: CVE-2018-1273
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-05T03:51:48.994Z
 NVD
                        NVD
                    Status : Modified
Published: 2018-04-11T13:29:00.290
Modified: 2025-10-22T00:16:22.233
Link: CVE-2018-1273
 Redhat
                        Redhat