'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2018-1270: Spring Messaging Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2018-1270
| Descripiton:
|
Spring is a lightweight Java development framework. Code injection vulnerabilities exist in Spring Framework versions 5.0 prior to 5.0.5, 4.3 versions prior to 4.3.15, and older versions that are no longer supported. The vulnerability stems from the lack of security measures such as authentication, access control, and rights management in network systems or products. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.