In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
References
Link | Resource |
---|---|
https://spring.io/security/cve-2024-37084 | Vendor Advisory |
https://spring.io/security/cve-2024-37084 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-07-25 10:15
Updated : 2024-11-21 09:23
NVD link : CVE-2024-37084
Mitre link : CVE-2024-37084
CVE.ORG link : CVE-2024-37084
JSON object : View
Products Affected
vmware
- spring_cloud_data_flow
CWE