关于应用是否存在CVE-2018-1270 Spring Framework漏洞的确认请求
Great question—let's break this down clearly to give you a definitive answer:
First, what is CVE-2018-1270?
CVE-2018-1270 is a remote code execution vulnerability that only targets the STOMP protocol handling in Spring WebSocket. For this vulnerability to be exploitable, two non-negotiable conditions must be met:
- The application uses Spring WebSocket (and includes the corresponding dependencies).
- The application explicitly enables STOMP support (via code like
@EnableWebSocketMessageBrokeror equivalent XML configuration).
Applying this to your application
Based on your description, your app checks neither of these boxes:
- You’re not using Spring WebSocket or any form of WebSocket dependencies: The code paths containing the vulnerability don’t exist in your application at all. Without the Spring WebSocket jars, there’s simply no surface for the exploit to target.
- You have no code references enabling STOMP support: Even if you did have WebSocket dependencies (which you don’t), without configuring STOMP message brokering, the vulnerable logic never gets activated.
A quick note on your Spring versions
While your spring-web (4.3.12.RELEASE) falls within the version range initially cited as affected by CVE-2018-1270 (4.3.x up to 4.3.13), that vulnerability only applies to applications using the Spring WebSocket + STOMP stack. Since you’re not using that stack, the version number here is irrelevant to this specific CVE.
Final conclusion
Your application does not face any risk from CVE-2018-1270.
内容的提问来源于stack exchange,提问作者devu

