Allocation of Resources Without Limits or Throttling in Pivotal Spring Data Commons and Pivotal Spring Data REST - CVE-2018-1274
Published: April 26, 2023
Vulnerability identifier: #VU75519
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1274
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in the property path parser, caused by unlimited resource allocation. A remote attacker can send specially crafted HTTP requests to the application and consume all available CPU and memory resources.
Affected software
Pivotal Spring Data Commons
Pivotal Spring Data REST
Autodesk Infraworks
Pivotal Spring Data REST
Autodesk Infraworks
How to mitigate CVE-2018-1274
Install updates from vendor's website.
Pivotal Spring Data Commons - addressed in versions 1.13.11, 2.0.6
Pivotal Spring Data REST - addressed in versions 2.6.11, 3.0.6
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Pivotal Spring Data REST - addressed in versions 2.6.11, 3.0.6
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1