StackRadar

CVE-2018-1259

High

Advisory

Published 17 Oct 2018In the index since 21 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.049
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1
of 17,821 indexed, latest versions
Container images
1
deployed by those charts
Fix available
1 of 1
affected package

Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references

Carried by container images the latest versions of 1 of 17,821 indexed charts deploy, on 1 image.

Affected packageAffected versionsFixed inImages
spring-data-commonsmaven2.0.5.RELEASE2.0.71
OSV records
GHSA-m929-7fr6-cvjg

Charts affected

1 by stars
ChartLatestAffected imagesRadar Score
opsmx-autopilotopsmxVerified publisher2.0.01 of 2See more

opsmx-autopilot opsmx 2.0.0

1 of the 2 container images this version deploys carry CVE-2018-1259.

Container imageDigestPackageFixed in
opsmxdev/ubi8-autopilot:v2.9.10-202006181240c7e4ea797f11
spring-data-commons@2.0.5.RELEASE
2.0.7

Open the chart page →

39,228

Container images carrying it

1 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opsmxdev/ubi8-autopilot:v2.9.10-202006181240c7e4ea797f11
spring-data-commons@2.0.5.RELEASE
2.0.7
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.