Privilege Escalation Vulnerability in Spring Framework by VMware
CVE-2021-22118
7.8HIGH
Summary
In the Spring Framework, specifically in versions preceding 5.2.15 and 5.3.7, there exists a vulnerability that allows a locally authenticated attacker to perform privilege escalation. This occurs due to improper handling of temporary storage directories. A malicious user could exploit this flaw by (re)creating these directories, gaining unauthorized access to read, modify, or overwrite files uploaded to the WebFlux application using multipart requests.
Affected Version(s)
Spring Framework Spring Framework versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved