CVE-2021-22118: High severity IBM DRM vulnerability
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Other sources
VMware Tanzu Spring Framework could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the WebFlux application. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges to read or modify files in the WebFlux application, or overwrite arbitrary files with multipart request data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.springframework:spring-webto a version that resolves this vulnerability.Fixed in 5.3.7 - Upgrade
Upgrade
maven/org.springframework:spring-webto a version that resolves this vulnerability.Fixed in 5.2.15 - Upgrade
Upgrade
redhat/spring-frameworkto a version that resolves this vulnerability.Fixed in 5.3.7 - Upgrade
Upgrade
redhat/spring-frameworkto a version that resolves this vulnerability.Fixed in 5.2.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.3.7 - Compensating control
If immediate upgrade is not possible, restrict access so that only trusted authenticated users can reach the WebFlux application endpoints affected by multipart/temporary storage handling, since a locally authenticated malicious user can exploit by (re)creating the temporary storage directory.
Event History
Parent advisories
This vulnerability appears in the following advisories.