cve-2017-8046
CRITICAL CVSS 10.0 csaf_redhat
Description
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
Timeline
- Published
- 2017-01-01 00:00 UTC
- Last Modified
- 2026-08-04
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Critical"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright © Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2017/cve-2017-8046.json"
}
],
"title": "spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code",
"tracking": {
"current_release_date": "2026-08-04T18:37:02+00:00",
"generator": {
"date": "2026-08-04T18:37:02+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.3.8"
}
},
"id": "CVE-2017-8046",
"initial_release_date": "2017-01-01T00:00:00+00:00",
"revision_history": [
{
"date": "2017-01-01T00:00:00+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-08-04T17:19:14+00:00",
"number": "2",
"summary": "Current version"
},
{
"date": "2026-08-04T18:37:02+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat OpenShift Application Runtimes",
"product": {
"name": "Red Hat OpenShift Application Runtimes",
"product_id": "red_hat_openshift_application_runtimes",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:openshift_application_runtimes:1.0"
}
}
}
],
"category": "product_family",
"name": "Red Hat OpenShift Application Runtimes"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R7",
"product": {
"name": "Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R7",
"product_id": "Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_fuse:6.3"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Fuse"
},
{
"category": "product_version",
"name": "spring-boot",
"product": {
"name": "spring-boot",
"product_id": "spring-boot",
"product_identification_helper": {
"purl": "pkg:maven/org.apache.camel.springboot/spring-boot?type=pom"
}
}
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "spring-boot as a component of Red Hat OpenShift Application Runtimes",
"product_id": "red_hat_openshift_application_runtimes:spring-boot"
},
"product_reference": "spring-boot",
"relates_to_product_reference": "red_hat_openshift_application_runtimes"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2017-8046",
"discovery_date": "2018-03-08T00:00:00+00:00",
"flags": [
{
"label": "vulnerable_code_not_present",
"product_ids": [
"red_hat_openshift_application_runtimes:spring-boot"
]
}
],
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "1553024"
}
],
"notes": [
{
"category": "description",
"text": "Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code",
"title": "Vulnerability summary"
},
{
"category": "other",
"text": "While there might be compatibility issues upgrading Spring REST Data independently of the Spring Boot version we recommend that customers make sure they are using a fixed version of Spring Data REST 2.6.9, or 3.0.1. RHOAR has now upgraded to version 1.5.10 of Spring Boot which is compatible with fixed versions of Spring DATA Rest.",
"title": "Statement"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R7"
],
"known_not_affected": [
"red_hat_openshift_application_runtimes:spring-boot"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2017-8046"
},
{
"category": "external",
"summary": "RHBZ#1553024",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1553024"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2017-8046",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-8046"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2017-8046",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-8046"
}
],
"release_date": "2018-03-06T00:00:00+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2018-08-14T19:51:07+00:00",
"details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.\n\nUpdating instructions and release notes may be found at:\n\nhttps://access.redhat.com/articles/3060411",
"product_ids": [
"Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R7"
],
"url": "https://access.redhat.com/errata/RHSA-2018:2405"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
},
"products": [
"Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R7",
"red_hat_openshift_application_runtimes:spring-boot"
]
}
],
"threats": [
{
"category": "impact",
"details": "Critical",
"product_ids": [
"Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R7",
"red_hat_openshift_application_runtimes:spring-boot"
]
}
],
"title": "spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code"
}
]
}
Enrichment data
Aggregated bundle (all enrichments)