CVE advisoryCRITICAL
CVE-2018-1270
Spring Framework STOMP WebSocket Remote Code Execution
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical vulnerability in Spring Framework's STOMP over WebSocket functionality allows unauthenticated attackers to achieve remote code execution by sending a crafted message. This impacts applications using the affected messaging module, potentially leading to system compromise.