Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfwj-fwqj-fp3v

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Improper Privilege Management in Spring Framework

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Пакеты

Наименование

org.springframework:spring-web

maven
Затронутые версииВерсия исправления

>= 5.2.0, <= 5.2.14

5.2.15

Наименование

org.springframework:spring-web

maven
Затронутые версииВерсия исправления

>= 5.3.0, <= 5.3.6

5.3.7

EPSS

Процентиль: 49%
0.00253
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-668

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.1
redhat
около 4 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.8
nvd
около 4 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.8
debian
около 4 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x ...

CVSS3: 7.8
fstec
около 4 лет назад

Уязвимость программной платформы Spring Framework, вызваная ошибками управления привилегиями, позволяющая нарушителю читать и перезаписывать произвольные файлы

EPSS

Процентиль: 49%
0.00253
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-668