In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Netapp
Subscribe
|
|
|
Oracle
Subscribe
|
Commerce Guided Search
Subscribe
Communications Brm - Elastic Charging Engine
Subscribe
Communications Cloud Native Core Binding Support Function
Subscribe
Communications Cloud Native Core Policy
Subscribe
Communications Cloud Native Core Security Edge Protection Proxy
Subscribe
Communications Cloud Native Core Service Communication Proxy
Subscribe
Communications Cloud Native Core Unified Data Repository
Subscribe
Communications Diameter Intelligence Hub
Subscribe
Communications Element Manager
Subscribe
Communications Interactive Session Recorder
Subscribe
Communications Network Integrity
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Communications Unified Inventory Management
Subscribe
Documaker
Subscribe
Enterprise Data Quality
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Healthcare Data Repository
Subscribe
Insurance Policy Administration
Subscribe
Insurance Rules Palette
Subscribe
Mysql Enterprise Monitor
Subscribe
Retail Assortment Planning
Subscribe
Retail Customer Management And Segmentation Foundation
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Merchandising System
Subscribe
Retail Order Broker
Subscribe
Retail Predictive Application Server
Subscribe
Utilities Testing Accelerator
Subscribe
|
|
Redhat
Subscribe
|
|
|
Vmware
Subscribe
|
Spring Framework
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3947 | In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data. |
Github GHSA |
GHSA-gfwj-fwqj-fp3v | Improper Privilege Management in Spring Framework |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-03T18:30:23.944Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-22118
No data.
Status : Modified
Published: 2021-05-27T15:15:07.437
Modified: 2024-11-21T05:49:32.563
Link: CVE-2021-22118
OpenCVE Enrichment
No data.
EUVD
Github GHSA