ZeroHour

CVE-2021-22118

CVSS 3.1
7.8 high
EPSS
<1%p33
Published
()
Modified
Description

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Vendors
vmwareoraclenetapp
Products
spring framework, commerce guided search, communications brm - elastic charging engine, communications cloud native core binding support function, communications cloud native core policy, communications cloud native core security edge protection proxy, communications cloud native core service communication proxy, communications cloud native core unified data repository, communications diameter intelligence hub, communications element manager, communications interactive session recorder, communications network integrity
Weakness
CWE-269, CWE-668
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.