CVE-2018-1273
KEV · ransomware Critical · CVSS 9.8Spring Data Commons — SpEL injection / remote code execution via property binder
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- oss containerizable
- CWE-94, NVD-CWE-Other
Description
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Search profile — drives PoC discovery
Ranked PoCs (42) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 10
- ★ 0
- ★ 0
- ★ 24
- ★ 58
- ★ 2webr0ck/poc-cve-2018-1273 needs reviewgh_search · Java
- ★ 0Agilevatester/SpringSecurity needs reviewtrickest
- ★ 0Agilevatester/SpringSecurityV1 needs reviewtrickest
- ★ 0CLincat/vulcat needs reviewtrickest
- ★ 0HackJava/HackSpring needs reviewtrickest
- ★ 0HackJava/Spring needs reviewtrickest
- ★ 0Ljw1114/SpringFramework-Vul needs reviewtrickest
- ★ 0NorthShad0w/FINAL needs reviewtrickest
- ★ 0PuddinCat/GithubRepoSpider needs reviewtrickest
- ★ 0Secxt/FINAL needs reviewtrickest
- ★ 0SexyBeast233/SecBooks needs reviewtrickest
- ★ 0SugarP1g/LearningSecurity needs reviewtrickest
- ★ 0Tim1995/FINAL needs reviewtrickest
- ★ 0Whoopsunix/PPPVULNS needs reviewtrickest
- ★ 0asa1997/topgear_test needs reviewtrickest
- ★ 0ax1sX/SpringSecurity needs reviewtrickest
- ★ 0bkhablenko/CVE-2017-8046 needs reviewtrickest
- ★ 0
- ★ 0huimzjty/vulwiki needs reviewtrickest
- ★ 0ilmari666/cybsec needs reviewtrickest
- ★ 0j5s/HacLang needs reviewtrickest
- ★ 0j5s/HacLang-1 needs reviewtrickest
- ★ 0jiangsir404/POC-S needs reviewtrickest
- ★ 0just0rg/Security-Interview needs reviewtrickest
- ★ 0langu-xyz/JavaVulnMap needs reviewtrickest
- ★ 0lnick2023/nicenice needs reviewtrickest
- ★ 0nBp1Ng/FrameworkAndComponentVulnerabilities needs reviewtrickest
- ★ 0nBp1Ng/SpringFramework-Vul needs reviewtrickest
- ★ 0onewinner/VulToolsKit needs reviewtrickest
- ★ 0qiuluo-oss/Tiger needs reviewtrickest
- ★ 0seal-community/patches needs reviewtrickest
- ★ 0snowlovely/HacLang needs reviewtrickest
- ★ 0superlink996/chunqiuyunjingbachang needs reviewtrickest
- ★ 0tomoyamachi/gocarts needs reviewtrickest
- ★ 0whoadmin/pocs needs reviewtrickest
- ★ 0zhengjim/loophole needs reviewtrickest
- ★ 0zisigui123123s/FINAL needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Maven | org.springframework.data:spring-data-commons | 1.13.0 → 1.13.11 |
| Maven | org.springframework.data:spring-data-commons | 2.0.0 → 2.0.6 |
References
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
- https://pivotal.io/security/cve-2018-1273
- https://www.oracle.com/security-alerts/cpujul2022.html
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
- https://pivotal.io/security/cve-2018-1273
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1273
Status: enriched · ingested 2026-06-16T00:00:58.000Z · profiled 2026-06-16T18:19:23.017Z