CVE Database
/

CVE-2018-1196

Back to search

CVE-2018-1196

Published: Mar 19, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the "run_user" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible.

VendorProductVersions

Dell EMC

Spring Boot

affected
1.5.0 - 1.5.9
affected
2.0.0.M1 - 2.0.0.M7

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now