CVE-2021-22118
—CVSS 3.1
7.8 high
EPSS
<1%p33
Published
()
Modified
Description
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
- Vendors
- vmwareoraclenetapp
- Products
- spring framework, commerce guided search, communications brm - elastic charging engine, communications cloud native core binding support function, communications cloud native core policy, communications cloud native core security edge protection proxy, communications cloud native core service communication proxy, communications cloud native core unified data repository, communications diameter intelligence hub, communications element manager, communications interactive session recorder, communications network integrity
- Weakness
- CWE-269, CWE-668
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.