CVE Vulnerabilities

CVE-2021-22118

Improper Privilege Management

Published: May 27, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Spring_frameworkVmware5.2.0 (including)5.2.15 (excluding)
Spring_frameworkVmware5.3.0 (including)5.3.7 (excluding)
Red Hat Fuse 7.10RedHatspring-web*
Red Hat IntegrationRedHat*
Red Hat IntegrationRedHatspring-web*
Libspring-javaUbuntuesm-apps/xenial*
Libspring-javaUbuntutrusty*
Libspring-javaUbuntuupstream*
Libspring-javaUbuntuxenial*

Potential Mitigations

References