CVE-2017-8046

Description

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
93.978

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-8046 are fixed in Spring - Data-rest-core 2.6.9Windows
Vulnerabilities CVE-2017-8046 are fixed in Spring - Data-rest-core 3.0.1Windows
Vulnerabilities CVE-2017-8046 are fixed in Spring - Data-rest-core for Linux 2.6.9Linux
Vulnerabilities CVE-2017-8046 are fixed in Spring - Data-rest-core for Linux 3.0.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234