PT-2024-4070 · Unknown · Spring Cloud Data Flow

Cokebeer

+3

·

Published

2024-05-23

·

Updated

2024-10-02

·

CVE-2024-22263

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Spring Cloud Data Flow (affected versions not specified)
Description: The issue is related to improper sanitization for upload paths in the Skipper server, allowing a malicious user with access to the server API to write arbitrary files to any location on the file system. This could potentially compromise the server. The vulnerability is associated with unlimited file uploads of dangerous types, which can be exploited by a remote attacker to write arbitrary files.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-04517
CVE-2024-22263

Affected Products

Spring Cloud Data Flow