CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2018-1273

KEV · ransomware Critical · CVSS 9.8

Spring Data Commons — SpEL injection / remote code execution via property binder

CVSS
9.8
nvd
EPSS
KEV
Listed
ransomware
Class
oss containerizable
CWE-94, NVD-CWE-Other

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Search profile — drives PoC discovery

Symbols MapDataBinderProjectingMethodInterceptorProxyProjectionFactoryMapPropertyAccessorSpelExpressionspelExpressionParserEvaluationContextStandardEvaluationContextRepositoryPropertyAccessorprojection-based request payload bindingSpring Data REST
Keywords CVE-2018-1273Spring Data Commons RCESpring Data REST property binder exploitSpEL injection Spring DataSpring Data Commons PoCMapDataBinder exploitSpring Data Commons 1.13Spring Data Commons 2.0projection binding RCESpring Data REST unauthenticated RCE
Versions: 1.13.0 to 1.13.9, 2.0.0 to 2.0.4 (and older unsupported versions)

Ranked PoCs (42) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Maven org.springframework.data:spring-data-commons 1.13.0 → 1.13.11
Maven org.springframework.data:spring-data-commons 2.0.0 → 2.0.6

References

Status: enriched · ingested 2026-06-16T00:00:58.000Z · profiled 2026-06-16T18:19:23.017Z