Lucene search

K
cveVmwareCVE-2024-22263
HistoryJun 19, 2024 - 3:15 p.m.

CVE-2024-22263

2024-06-1915:15:58
CWE-434
vmware
web.nvd.nist.gov
39
20
spring cloud data flow
skipper server
upload request
file system
security vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0

Percentile

9.0%

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Spring Cloud Skipper",
    "vendor": "Spring by VMware Tanzu",
    "versions": [
      {
        "status": "affected",
        "version": "2.11.0 - 2.11.2, 2.10.x"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2024-22263