In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2024-37084 |
Configurations
No configuration.
History
No history.
Information
Published : 2024-07-25 10:15
Updated : 2024-07-25 12:36
NVD link : CVE-2024-37084
Mitre link : CVE-2024-37084
CVE.ORG link : CVE-2024-37084
JSON object : View
Products Affected
No product.
CWE
No CWE.
