CVE Database
/

CVE-2021-22118

Back to search

CVE-2021-22118

Published: May 27, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

VendorProductVersions

n/a

Spring Framework

affected
Spring Framework versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now