Arbitrary File Write Vulnerability in Spring Cloud Data Flow
Published Jun 19, 2024
8.8
HIGHCVSS 3.1
EPSS 17.54%
Description
Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.
Affected products
-
Affected
- 2.11.0 - 2.11.2, 2.10.x
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Spring by VMware Tanzu | Spring Cloud Skipper | unaffected | Affected
|
No data.
-
Affected
- 2.10.x
- ≥ 2.11.0, ≤ 2.11.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Spring BY Vmware Tanzu | Spring Cloud Skipper | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data