Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2024-22263 |
|
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-01T22:43:33.729Z
Reserved: 2024-01-08T18:43:17.077Z
Link: CVE-2024-22263
Updated: 2024-08-01T22:43:33.729Z
Status : Awaiting Analysis
Published: 2024-06-19T15:15:58.327
Modified: 2024-11-21T08:55:55.223
Link: CVE-2024-22263
No data.
OpenCVE Enrichment
No data.
Weaknesses