In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Project Subscriptions

Vendors Products
Management Services For Element Software Subscribe
Commerce Guided Search Subscribe
Communications Brm - Elastic Charging Engine Subscribe
Communications Cloud Native Core Binding Support Function Subscribe
Communications Cloud Native Core Policy Subscribe
Communications Cloud Native Core Security Edge Protection Proxy Subscribe
Communications Cloud Native Core Service Communication Proxy Subscribe
Communications Cloud Native Core Unified Data Repository Subscribe
Communications Diameter Intelligence Hub Subscribe
Communications Element Manager Subscribe
Communications Interactive Session Recorder Subscribe
Communications Network Integrity Subscribe
Communications Session Report Manager Subscribe
Communications Session Route Manager Subscribe
Communications Unified Inventory Management Subscribe
Documaker Subscribe
Enterprise Data Quality Subscribe
Financial Services Analytical Applications Infrastructure Subscribe
Healthcare Data Repository Subscribe
Insurance Policy Administration Subscribe
Insurance Rules Palette Subscribe
Mysql Enterprise Monitor Subscribe
Retail Assortment Planning Subscribe
Retail Customer Management And Segmentation Foundation Subscribe
Retail Financial Integration Subscribe
Retail Integration Bus Subscribe
Retail Merchandising System Subscribe
Retail Order Broker Subscribe
Retail Predictive Application Server Subscribe
Utilities Testing Accelerator Subscribe
Integration Subscribe
Jboss Fuse Subscribe
Spring Framework Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3947 In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Github GHSA Github GHSA GHSA-gfwj-fwqj-fp3v Improper Privilege Management in Spring Framework
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2024-08-03T18:30:23.944Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-22118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-27T15:15:07.437

Modified: 2024-11-21T05:49:32.563

Link: CVE-2021-22118

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-25T00:00:00Z

Links: CVE-2021-22118 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses