In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
PoC: CVE-2024-37084-Exp
Spring Cloud Data Flow CVE-2024-37084 exp
PoC: cve-2024-37084-Poc
CVE-2024-37084是Spring Cloud Data Flow中的一个高危漏洞,影响版本为2.11.0至2.11.3。该漏洞允许具有Skipper服务器API访问权限的攻击者通过精心构造的上传请求,将任意文件写入服务器文件系统的任意位置,进而可能导致远程代码执行,严重威胁服务器安全。
PoC: CVE-2024-37084-Exp
Spring Cloud Data Flow CVE-2024-37084 exp
PoC: CVE-2024-37084
Spring Cloud Remote Code Execution
PoC: CVE-2024-37084-Poc
Analysis , Demo exploit and poc about CVE-2024-37084
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free