CVE-2018-1270: Code Injection
Pivotal Spring Framework could allow a remote attacker to execute arbitrary code on the system, caused by the exposure of STOMP over WebSocket endpoints with a STOMP broker through the spring-messaging module. By sending a specially-crafted message, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Other sources
Spring Framework allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
External References:
https://pivotal.io/security/cve-2018-1270
— Red Hat
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
— GitHub
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1270?
The severity of CVE-2018-1270 is rated as high due to its potential to allow remote code execution.
How do I fix CVE-2018-1270?
To fix CVE-2018-1270, update to the latest versions of Spring Framework 4.3.16.RELEASE or 5.0.5.RELEASE.
Who is affected by CVE-2018-1270?
CVE-2018-1270 affects users of the Pivotal Spring Framework using specific versions that expose STOMP over WebSocket endpoints.
What type of attack can exploit CVE-2018-1270?
CVE-2018-1270 can be exploited through specially-crafted messages sent to the application's STOMP broker.
When was CVE-2018-1270 published?
CVE-2018-1270 was published on April 19, 2018.