References https://pivotal.io/security/cve-2017-8046 https://tech.meituan.com/2017/09/29/spring-data-rest-cve.html https://zhuanlan.zhihu.com/p/29828417 https://spring.io/security/cve-2017-8046 https://yaofeifly.github.io/2017/10/11/Spring-Data-Rest/ https://www.cnblogs.com/sallyzhang/p/12401604.html https://securitylab.github.com/research/spring-data-rest-CVE-2017-8046-ql/ https://nsfocusglobal.com/analysis-and-solution-of-spring-data-rest-server-patch-request-rce-vulnerability/ https://www.exploit-db.com/exploits/44289 https://blog.spoock.com/2018/05/22/cve-2017-8046/ https://nvd.nist.gov/vuln/detail/CVE-2017-8046
Related VulnerabilitiesSpringBlade /api/blade-log/api/list SQL 注入漏洞SpringBlade /api/blade-user/list SQL 注入漏洞Spring Actuator 未授权访问漏洞PoCspringboot-sbom: Spring Boot Actuator SBOM - ExposurePoCCVE-2025-41242: Spring Framework - Path TraversalPoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksPentaho /pentaho/j_spring_security_check 默认口令漏洞PoCCVE-2026-22739: Spring Cloud Config Server - Path TraversalPoCspringboot-x-application-context: Spring Boot `X-Application-Context` Header ExposureSpring Framework路径遍历漏洞(CVE-2024-38819)Spring Cloud Gateway SpEL 表达式注入漏洞