VYPR

Spring Cloud Dataflow

by Spring Cloud

Source repositories

CVEs (3)

  • CVE-2024-22263HigJun 19, 2024
    risk 0.63cvss 8.8epss 0.18

    Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to…

  • CVE-2024-37084Jul 25, 2024
    risk 0.07cvss epss 0.35

    In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

  • CVE-2020-5427Jan 27, 2021
    risk 0.00cvss epss 0.01

    In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.