VMware Spring Cloud Data Flow是美国威睿(VMware)公司的一款用于微服务中流式处理和批处理数据的代码库。 VMware Spring Cloud Data Flow存在安全漏洞,该漏洞源于。上传路径的清理不当,攻击者可以使用精心设计的上传请求将任意文件写入文件系统上的任何位置,甚至可能破坏服务器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring by VMware Tanzu | Spring Cloud Skipper | 2.11.0 - 2.11.2, 2.10.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | (CVE-2024-22263) Spring Cloud Dataflow Arbitrary File Writing Scanner | https://github.com/securelayer7/CVE-2024-22263_Scanner | POC Details |
No public POC found.
Login to generate AI POCNo comments yet