Known vulnerabilities in Spring Cloud Data Flow
Vendor:
Broadcom
Software:
Spring Cloud Data Flow
Software CPE:
cpe:2.3:a:broadcom:spring_cloud_data_flow:*:*:*:*:*:*:*:*
Website:
https://www.broadcom.com/
Total vulnerabilities:
3
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
2.11.5
2.11.4
2.11.3
2.11.2
2.11.1
2.11.0-RC1
2.10.3
2.11.0
2.10.2
2.10.1
2.10.0
2.10.0-RC2
2.10.0-RC1
2.10.0-M2
2.9.6
2.9.5
2.9.4
2.9.3
2.10.0-M1
2.9.2
2.9.1
2.8.4
2.9.0-RC1
2.8.0-RC1
2.9.0
2.8.3
2.9.0-M2
2.8.2
2.9.0-M1
2.8.1
2.8.0
2.8.0-M1
2.7.2
1.0.0.M1
1.0.0.M2
2.7.1
2.7.0-RC1
2.7.0-M2
2.7.0-M1
2.7.0
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0-RC1
2.6.0-M2
2.6.0-M1
2.6.0
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0.RC1
2.5.0.M1
2.5.0
2.4.2
2.4.1
2.4.0.RC1
2.4.0.M2
2.4.0.M1
2.4.0
2.3.1
2.3.0.RC2
2.3.0.RC1
2.3.0.M2
2.3.0.M1
2.3.0
2.2.3
2.2.2
2.2.1
2.2.0.RC1
2.2.0.M1
2.2.0
2.1.2
2.1.1
2.1.0.RC1
2.1.0.M1
2.1.0
2.0.3
2.0.2
2.0.1
2.0.0.RC1
2.0.0.M2
2.0.0.M1
2.0.0
1.7.4
1.7.3
1.7.2
1.7.1
1.7.0.RC1
1.7.0.M1
1.7.0
1.6.3
1.6.2
1.6.1
1.6.0.RC1
1.6.0.M2
1.6.0.M1
1.6.0
1.5.2
1.5.1
1.5.0.RC1
1.5.0.M1
1.5.0
1.4.1
1.4.0.RC1
1.4.0.M1
1.4.0
1.3.1
1.3.0.RC2
1.3.0.RC1
1.3.0.M3
1.3.0.M2
1.3.0.M1
1.3.0
1.2.3
1.2.2
1.2.1
1.2.0.RC2
1.2.0.RC1
1.2.0.M3
1.2.0.M2
1.2.0.M1
1.2.0
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0.RC1
1.1.0.M2
1.1.0.M1
1.1.0
1.0.1
1.0.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU94730 - Unrestricted Upload of File with Dangerous Type CVE-2024-37084 |
CWE-434 | Medium | 2.11.4 | 25.07.2024 |
SB2024072513 |
||
| #VU89866 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-22263 |
CWE-22 | Medium | 2.11.3 | 29.05.2024 |
SB2024052920 |
||
| #VU49985 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2020-5427 |
CWE-89 | Low | 2.5.4, 2.6.5 | 25.01.2021 |
SB2021012527 |