← Back to browse · API

CVE-2024-37084

Severity
CRITICAL
CVSS
9.8
EPSS
0.35211
Risk score
51.52
CISA KEV
No
PoC
No
Published
2024-07-25
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-2389, GHSA-P528-3MVF-GR87
Products
Spring:Spring Cloud Data Flow 2.11.x <2.11.4
Sources
euvd EUVD-2024-2389

Description

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

References