Allocation of Resources Without Limits or Throttling in Pivotal Spring Data Commons and Pivotal Spring Data REST - CVE-2018-1274

 

Allocation of Resources Without Limits or Throttling in Pivotal Spring Data Commons and Pivotal Spring Data REST - CVE-2018-1274

Published: April 26, 2023


Vulnerability identifier: #VU75519
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1274
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error in the property path parser, caused by unlimited resource allocation. A remote attacker can send specially crafted HTTP requests to the application and consume all available CPU and memory resources.


Affected software

Pivotal Spring Data Commons
Pivotal Spring Data REST
Autodesk Infraworks

How to mitigate CVE-2018-1274

Install updates from vendor's website.

Pivotal Spring Data Commons - addressed in versions 1.13.11, 2.0.6
Pivotal Spring Data REST - addressed in versions 2.6.11, 3.0.6
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1

External References

Related Security Bulletins