CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
Published Jul 25, 2024
·Updated
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
Affected Software
2 affected componentsFixes available
maven/org.springframework.cloud:spring-cloud-skipper<2.11.4
2.11.4
VMware Spring Cloud Data Flow>=2.11.0<2.11.4
Event History
Jul 25, 2024
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-37084?
CVE-2024-37084 is considered a critical vulnerability due to its potential to allow arbitrary file write access on the server.
2
How do I fix CVE-2024-37084?
To fix CVE-2024-37084, upgrade Spring Cloud Data Flow to version 2.11.4 or later.
3
Who is affected by CVE-2024-37084?
CVE-2024-37084 affects users of Spring Cloud Data Flow versions prior to 2.11.4.
4
What is the impact of CVE-2024-37084?
The impact of CVE-2024-37084 is that it could allow an attacker to compromise the server by writing malicious files.
5
What component of Spring Cloud Data Flow does CVE-2024-37084 affect?
CVE-2024-37084 specifically affects the Skipper server API component of Spring Cloud Data Flow.