Back

HIGH

Arbitrary File Write Vulnerability in Spring Cloud Data Flow

Published Jun 19, 2024

Description

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner vmware
Published Jun 19, 2024
Updated Aug 1, 2024
Reserved Jan 8, 2024

CISA Vulnrichment

Updated Jun 20, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner vmware
Published Jun 19, 2024
Updated Aug 1, 2024

GitHub

No data