ID:10458 - Exploit for Path traversal in Spring Cloud Data Flow - CVE-2024-22263
Published: August 30, 2024
Spring Cloud Data Flow
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing file upload requests within the Skipper server API. A remote user can use a crafted upload request to write arbitrary file to any location on file system, resulting in full system compromise.