« Volver al listado

CVE-2018-1196

Estado: ModificadaMedia (5.9)—

Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the "run_user" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-1196",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell EMC",
          "product": "Spring Boot",
          "versions": [
            {
              "status": "affected",
              "version": "1.5.0 - 1.5.9"
            },
            {
              "status": "affected",
              "version": "2.0.0.M1 - 2.0.0.M7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-03-19T18:29:00.387",
  "references": [
    {
      "url": "https://pivotal.io/security/cve-2018-1196",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://pivotal.io/security/cve-2018-1196",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the \"run_user\" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the \"run_user\" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible."
    },
    {
      "lang": "es",
      "value": "Spring Boot soporta un script de inicio embebido que puede emplearse para ejecuta fácilmente la aplicación como servicio de linux systemd o init.d. El script incluido con Spring Boot 1.5.9 y anteriores y 2.0.0.M1 hasta 2.0.0.M7 es susceptible a un ataque symlink que permite que \"run_user\" sobrescriba y se haga dueño de cualquier archivo en el mismo sistema. Para instigar el ataque, la aplicación debe estar instalada como servicio y \"run_user\" requiere acceso shell al servidor. Las aplicaciones Spring Boot que no estén instaladas como servicio o que no estén usando el script de inicio embebido no son susceptibles."
    }
  ],
  "lastModified": "2026-06-17T01:50:41.020",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "777814DB-A842-44AE-80AA-DAAB0F0C2DE8",
              "versionEndIncluding": "1.5.9"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:2.0.0:milestone1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "141F2C99-AD34-4003-81D4-689F3F1A53ED"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:2.0.0:milestone2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7929E66-FCA2-4D1B-B29F-55BF70AF70C2"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:2.0.0:milestone3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6B93CDA-E5D9-4955-910A-22B38779F23C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:2.0.0:milestone4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F324F68E-CF50-4F2E-90E4-3620CE05A944"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:2.0.0:milestone5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C120785F-A827-4870-B33B-679367A9EB20"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:2.0.0:milestone6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4826AF0C-1C00-4E13-88D0-2803A3BC01DC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:2.0.0:milestone7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F6E42D8-3B40-4EC5-ACA4-3055F64A2AD4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}