CVE-2017-8046 is a code-injection vulnerability in Spring Data REST's handling of PATCH requests. A remote attacker can submit specially crafted JSON in a PATCH request to a server running a vulnerable Spring Data REST version, causing arbitrary Java code to execute. Affected versions include Spring Data REST releases before 2.6.9.RELEASE in the 2.6.x line and before 3.0.1.RELEASE in the 3.0.x line; affected Spring Boot releases include versions before 1.5.9 and 2.0.0.M6.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Java-based exploit for CVE-2017-8046, a remote code execution vulnerability in Pivotal Spring Data REST (and related Spring Boot/Data versions). The exploit is implemented in a single Java file (SpringBreakCve20178046.java) and is designed to send malicious PATCH requests with specially crafted JSON payloads to vulnerable endpoints. The payload leverages Spring Expression Language (SpEL) injection to execute arbitrary system commands or upload files to the server. The exploit supports options for specifying the target URL, command to execute, file to upload, custom headers, cookies, and SSL validation skipping. The README provides detailed usage instructions, example commands, and a list of example vulnerable endpoints. The repository is structured as a Maven project, with a pom.xml for dependencies and build configuration. The exploit is operational and can be used to achieve RCE or file upload on vulnerable Java-based web applications using affected Spring Data REST versions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.