Description
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Published: 2021-05-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-3947 In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Github GHSA Github GHSA GHSA-gfwj-fwqj-fp3v Improper Privilege Management in Spring Framework
History

No history.

Subscriptions

Netapp Hci Management Services For Element Software
Oracle Commerce Guided Search Communications Brm - Elastic Charging Engine Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Policy Communications Cloud Native Core Security Edge Protection Proxy Communications Cloud Native Core Service Communication Proxy Communications Cloud Native Core Unified Data Repository Communications Diameter Intelligence Hub Communications Element Manager Communications Interactive Session Recorder Communications Network Integrity Communications Session Report Manager Communications Session Route Manager Communications Unified Inventory Management Documaker Enterprise Data Quality Financial Services Analytical Applications Infrastructure Healthcare Data Repository Insurance Policy Administration Insurance Rules Palette Mysql Enterprise Monitor Retail Assortment Planning Retail Customer Management And Segmentation Foundation Retail Financial Integration Retail Integration Bus Retail Merchandising System Retail Order Broker Retail Predictive Application Server Utilities Testing Accelerator
Redhat Integration Jboss Fuse
Vmware Spring Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2024-08-03T18:30:23.944Z

Reserved: 2021-01-04T00:00:00.000Z

Link: CVE-2021-22118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-27T15:15:07.437

Modified: 2024-11-21T05:49:32.563

Link: CVE-2021-22118

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-25T00:00:00Z

Links: CVE-2021-22118 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses