---
id: CVE-2018-1273
title: >-
  Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and
  older unsupported versions, contain a property binder vulnerability caused by
  improper neutralization of special elements
summary: >-
  Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and
  older unsupported versions, contain a property binder vulnerability caused by
  improper neutralization of special elements. An unauthenticated remote
  malicious user…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: broadcom
product: spring_data_commons
affected:
  - spring_data_commons <= 1.12.10
  - 'spring_data_commons >= 1.13.0, <= 1.13.10'
  - 'spring_data_commons >= 2.0.0, <= 2.0.5'
  - 'spring_data_rest >= 3.0.0, <= 3.0.5'
  - spring_data_rest <= 2.5.10
  - 'spring_data_rest >= 2.6.0, <= 2.6.10'
  - 'ignite >= 1.0.1, <= 2.5.0'
  - ignite = 1.0.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.2.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.3.0
published: '2018-04-11'
updated: '2026-06-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-1273'
references:
  - url: >-
      http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
    label: security_alert@emc.com
  - url: 'https://pivotal.io/security/cve-2018-1273'
    label: security_alert@emc.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security_alert@emc.com
  - url: >-
      http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://pivotal.io/security/cve-2018-1273'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1273
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.96956
epssPercentile: 0.99888
kev: true
kevDateAdded: '2022-03-25'
kevDueDate: '2022-04-15'
kevRansomware: true
exploited: true
ingestedAt: '2026-06-29T13:24:33.215Z'
exploits:
  github: 6
  githubRepos:
    - 'https://github.com/knqyf263/CVE-2018-1273'
    - 'https://github.com/wearearima/poc-cve-2018-1273'
    - 'https://github.com/webr0ck/poc-cve-2018-1273'
  nuclei:
    - CVE-2018-1273
  checkedAt: '2026-09-23T07:13:15.342Z'
exploitAvailable: true
---

## Overview

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

## Affected

- `spring_data_commons <= 1.12.10`
- `spring_data_commons >= 1.13.0, <= 1.13.10`
- `spring_data_commons >= 2.0.0, <= 2.0.5`
- `spring_data_rest >= 3.0.0, <= 3.0.5`
- `spring_data_rest <= 2.5.10`
- `spring_data_rest >= 2.6.0, <= 2.6.10`
- `ignite >= 1.0.1, <= 2.5.0`
- `ignite = 1.0.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
