Privilege Escalation Vulnerability in Spring Framework by VMware
CVE-2021-22118
7.8HIGH
What is CVE-2021-22118?
In the Spring Framework, specifically in versions preceding 5.2.15 and 5.3.7, there exists a vulnerability that allows a locally authenticated attacker to perform privilege escalation. This occurs due to improper handling of temporary storage directories. A malicious user could exploit this flaw by (re)creating these directories, gaining unauthorized access to read, modify, or overwrite files uploaded to the WebFlux application using multipart requests.
Affected Version(s)
Spring Framework Spring Framework versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7