Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Project Subscriptions

Vendors Products
Broadcom Subscribe
Spring Data Commons Subscribe
Pivotal Software Subscribe
Spring Data Rest Subscribe
Jboss Fuse Subscribe
Openshift Application Runtimes Subscribe
Xmlbeam Subscribe
Xmlbeam Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m929-7fr6-cvjg Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 15 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom spring Data Commons
CPEs cpe:2.3:a:pivotal_software:spring_data_commons:*:*:*:*:*:*:*:* cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*
Vendors & Products Pivotal Software spring Data Commons
Broadcom
Broadcom spring Data Commons

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T16:33:36.641Z

Reserved: 2017-12-06T00:00:00.000Z

Link: CVE-2018-1259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-11T20:29:00.307

Modified: 2026-06-17T01:50:50.290

Link: CVE-2018-1259

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-05-09T00:00:00Z

Links: CVE-2018-1259 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses