CVE Vulnerabilities

CVE-2024-37084

Published: Jul 25, 2024 | Modified: Aug 26, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

Affected Software

Name Vendor Start Version End Version
Spring_cloud_data_flow Vmware 2.11.0 (including) 2.11.4 (excluding)

References