CVE-2024-37084
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 35.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 35.21% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- vmware/spring cloud data flow
- Source
- security@vmware.com
References
- https://spring.io/security/cve-2024-37084Vendor Advisory
- https://spring.io/security/cve-2024-37084Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.