#VU89866 Path traversal in Spring Cloud Data Flow - CVE-2024-22263
Published: May 29, 2024 / Updated: August 30, 2024
Spring Cloud Data Flow
Pivotal
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing file upload requests within the Skipper server API. A remote user can use a crafted upload request to write arbitrary file to any location on file system, resulting in full system compromise.