ZeroHour

CVE-2024-37084

CVSS 3.1
8.8 high
EPSS
35%p98
Published
()
Modified
Description

In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

Vendors
vmware
Products
spring cloud data flow
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.