CVE-2018-1270 - CVE House
Back to Database
Status published Critical CVE-2018-1270

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3...

Vulnerability Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1270

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Spring by Pivotal

View all reports →

Affected Software

Spring Framework
Vulnerable Versions:
Versions prior to 5.0.5 and 4.3.15

Timeline

Official Publish: April 6th, 2018
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)