Critical severity9.8NVD Advisory· Published Jan 4, 2018· Updated Jun 26, 2026
CVE-2017-8046
CVE-2017-8046
Description
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.data:spring-data-rest-coreMaven | < 2.6.9.RELEASE | 2.6.9.RELEASE |
org.springframework.data:spring-data-rest-coreMaven | >= 3.0.0, < 3.0.1.RELEASE | 3.0.1.RELEASE |
Affected products
2- Pivotal/Pivotal Spring Data REST and Spring Bootv5Range: Pivotal Spring Data REST versions prior to 2.6.9 (Ingalls SR9), 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6
Patches
Vulnerability mechanics
References
10- www.securityfocus.com/bid/100948nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-9qf9-28h9-hqcjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-8046ghsaADVISORY
- pivotal.io/security/cve-2017-8046nvdVendor AdvisoryWEB
- www.exploit-db.com/exploits/44289/nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:2405nvdWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/spring-projects/spring-data-rest/issues/1487ghsaWEB
- github.com/spring-projects/spring-data-rest/issues/1520ghsaWEB
- jira.spring.io/browse/DATAREST-1127ghsaWEB
News mentions
0No linked articles in our index yet.