Critical severityNVD Advisory· Published Jul 25, 2024· Updated Aug 2, 2024
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
CVE-2024-37084
Description
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.cloud:spring-cloud-skipperMaven | < 2.11.4 | 2.11.4 |
Affected products
3- osv-coords2 versions
>= 2.11.0, < 2.11.4+ 1 more
- (no CPE)range: >= 2.11.0, < 2.11.4
- (no CPE)range: < 2.11.4
- Range: 2.11.x
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-p528-3mvf-gr87ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-37084ghsaADVISORY
- spring.io/security/cve-2024-37084ghsaWEB
News mentions
0No linked articles in our index yet.