Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37084


In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server


Published

2024-07-25T10:15:07.260

Last Modified

2024-11-21T09:23:09.750

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware spring_cloud_data_flow < 2.11.4 Yes

References