FixVibe

high

Spring Data Commons XMLBeam XXE (CVE-2018-1259)

Spring Data Commons CVE-2018-1259 is an XXE advisory that depends on affected Spring Data Commons and XMLBeam versions. FixVibe GitHub repo scans flag projects that use both.

CVE-2018-1259GHSA-m929-7fr6-cvjgGHSA-m929-7fr6-cvjgCWE-611

Impact

CVE-2018-1259 is an XML External Entity (XXE) advisory in Spring Data Commons web support when affected Spring Data Commons release lines are used with XMLBeam [S1][S2]. Successful exploitation depends on application-specific request payload projection paths and can expose XML entity processing risks such as local file disclosure or SSRF in vulnerable deployments [S1][S3].

Root cause

The Spring advisory describes unsafe XML external entity handling in a property binder path used with XMLBeam [S1]. The vulnerable setup requires affected Spring Data Commons versions and XMLBeam before the fixed XMLBeam release [S1][S5].

Affected versions

Spring lists Spring Data Commons 1.13 through 1.13.11 and 2.0 through 2.0.6 as affected, with fixes in 1.13.12 and 2.0.7 [S1]. GitHub Advisory Database and OSV record the Maven package org.springframework.data:spring-data-commons as affected in the ranges >=1.13.0 <1.13.12 and >=2.0.0 <2.0.7 [S2][S4]. XMLBeam should be upgraded to 1.4.15 or newer when it is present [S1][S5].

Fixes

Upgrade Spring Data Commons to a fixed release line, or move to a later supported Spring Data release. If XMLBeam is present, upgrade org.xmlbeam:xmlprojector to 1.4.15 or newer [S1][S5]. Rebuild the deployed JAR, WAR, or container image and verify the final dependency tree, not only the source manifest.

Covered by FixVibe

FixVibe's GitHub repo scans flag Maven or Gradle projects whose dependency graph includes both affected Spring Data Commons and affected XMLBeam versions, pointing to the files and versions to upgrade.