{"id":"GHSA-9qf9-28h9-hqcj","summary":"Remote code execution in PATCH requests in Spring Data REST","details":"Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) can use specially crafted JSON data to run arbitrary Java code.","aliases":["CVE-2017-8046"],"modified":"2023-11-01T04:48:22.360813Z","published":"2022-05-13T01:02:43Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-11-04T18:40:40Z","nvd_published_at":"2018-01-04T06:29:00Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-8046"},{"type":"WEB","url":"https://github.com/spring-projects/spring-data-rest/issues/1487"},{"type":"WEB","url":"https://github.com/spring-projects/spring-data-rest/issues/1520"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2405"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1553024"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-data-rest"},{"type":"WEB","url":"https://jira.spring.io/browse/DATAREST-1127?redirect=false"},{"type":"WEB","url":"https://pivotal.io/security/cve-2017-8046"}],"affected":[{"package":{"name":"org.springframework.data:spring-data-rest-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework.data/spring-data-rest-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.9.RELEASE"}]}],"versions":["1.0.0.RELEASE","2.0.0.RELEASE","2.0.1.RELEASE","2.0.2.RELEASE","2.0.3.RELEASE","2.1.0.RELEASE","2.1.1.RELEASE","2.1.2.RELEASE","2.1.4.RELEASE","2.1.5.RELEASE","2.1.6.RELEASE","2.2.0.RELEASE","2.2.1.RELEASE","2.2.2.RELEASE","2.2.3.RELEASE","2.2.4.RELEASE","2.3.0.RELEASE","2.3.1.RELEASE","2.3.2.RELEASE","2.4.0.RELEASE","2.4.1.RELEASE","2.4.2.RELEASE","2.4.4.RELEASE","2.4.5.RELEASE","2.4.6.RELEASE","2.5.0.RELEASE","2.5.1.RELEASE","2.5.10.RELEASE","2.5.11.RELEASE","2.5.2.RELEASE","2.5.3.RELEASE","2.5.4.RELEASE","2.5.5.RELEASE","2.5.6.RELEASE","2.5.7.RELEASE","2.5.8.RELEASE","2.5.9.RELEASE","2.6.0.RELEASE","2.6.1.RELEASE","2.6.2.RELEASE","2.6.3.RELEASE","2.6.4.RELEASE","2.6.5.RELEASE","2.6.6.RELEASE","2.6.7.RELEASE","2.6.8.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9qf9-28h9-hqcj/GHSA-9qf9-28h9-hqcj.json"}},{"package":{"name":"org.springframework.data:spring-data-rest-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework.data/spring-data-rest-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.1.RELEASE"}]}],"versions":["3.0.0.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9qf9-28h9-hqcj/GHSA-9qf9-28h9-hqcj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}