You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于应用是否存在CVE-2018-1270 Spring Framework漏洞的确认请求

Is My Application at Risk of CVE-2018-1270?

Great question—let's break this down clearly to give you a definitive answer:

First, what is CVE-2018-1270?

CVE-2018-1270 is a remote code execution vulnerability that only targets the STOMP protocol handling in Spring WebSocket. For this vulnerability to be exploitable, two non-negotiable conditions must be met:

  1. The application uses Spring WebSocket (and includes the corresponding dependencies).
  2. The application explicitly enables STOMP support (via code like @EnableWebSocketMessageBroker or equivalent XML configuration).

Applying this to your application

Based on your description, your app checks neither of these boxes:

  • You’re not using Spring WebSocket or any form of WebSocket dependencies: The code paths containing the vulnerability don’t exist in your application at all. Without the Spring WebSocket jars, there’s simply no surface for the exploit to target.
  • You have no code references enabling STOMP support: Even if you did have WebSocket dependencies (which you don’t), without configuring STOMP message brokering, the vulnerable logic never gets activated.

A quick note on your Spring versions

While your spring-web (4.3.12.RELEASE) falls within the version range initially cited as affected by CVE-2018-1270 (4.3.x up to 4.3.13), that vulnerability only applies to applications using the Spring WebSocket + STOMP stack. Since you’re not using that stack, the version number here is irrelevant to this specific CVE.

Final conclusion

Your application does not face any risk from CVE-2018-1270.

内容的提问来源于stack exchange,提问作者devu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:49:43