Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2018-01-04T06:00:00

Updated: 2018-08-15T09:57:01

Reserved: 2017-04-21T00:00:00


Link: CVE-2017-8046

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-01-04T06:29:00.307

Modified: 2022-04-07T15:03:14.400


Link: CVE-2017-8046

JSON object: View

cve-icon Redhat Information

No data.

CWE