Impact
CVE-2018-1259 is an XML External Entity (XXE) advisory in Spring Data Commons web support when affected Spring Data Commons release lines are used with XMLBeam [S1][S2]. Successful exploitation depends on application-specific request payload projection paths and can expose XML entity processing risks such as local file disclosure or SSRF in vulnerable deployments [S1][S3].
Root cause
The Spring advisory describes unsafe XML external entity handling in a property binder path used with XMLBeam [S1]. The vulnerable setup requires affected Spring Data Commons versions and XMLBeam before the fixed XMLBeam release [S1][S5].
Affected versions
Spring lists Spring Data Commons 1.13 through 1.13.11 and 2.0 through 2.0.6 as affected, with fixes in 1.13.12 and 2.0.7 [S1]. GitHub Advisory Database and OSV record the Maven package org.springframework.data:spring-data-commons as affected in the ranges >=1.13.0 <1.13.12 and >=2.0.0 <2.0.7 [S2][S4]. XMLBeam should be upgraded to 1.4.15 or newer when it is present [S1][S5].
Fixes
Upgrade Spring Data Commons to a fixed release line, or move to a later supported Spring Data release. If XMLBeam is present, upgrade org.xmlbeam:xmlprojector to 1.4.15 or newer [S1][S5]. Rebuild the deployed JAR, WAR, or container image and verify the final dependency tree, not only the source manifest.
Covered by FixVibe
FixVibe's GitHub repo scans flag Maven or Gradle projects whose dependency graph includes both affected Spring Data Commons and affected XMLBeam versions, pointing to the files and versions to upgrade.
