[MAVEN:GHSA-GFWJ-FWQJ-FP3V] Improper Privilege Management in Spring Framework

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Package Affected Version
pkg:maven/org.springframework/spring-web >= 5.3.0, <= 5.3.6
pkg:maven/org.springframework/spring-web >= 5.2.0, <= 5.2.14
ID
MAVEN:GHSA-GFWJ-FWQJ-FP3V
Severity
high
URL
https://github.com/advisories/GHSA-gfwj-fwqj-fp3v
Published
2022-05-24T19:03:28
(2 years ago)
Modified
2023-07-19T14:39:30
(14 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.springframework/spring-web org.springframework spring-web >= 5.3.0 <= 5.3.6
Fixed pkg:maven/org.springframework/spring-web org.springframework spring-web = 5.3.7
Affected pkg:maven/org.springframework/spring-web org.springframework spring-web >= 5.2.0 <= 5.2.14
Fixed pkg:maven/org.springframework/spring-web org.springframework spring-web = 5.2.15
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...