Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不安全的临时文件
Vulnerability Title
VMware Spring Boot 安全漏洞
Vulnerability Description
VMware Spring Boot是美国威睿(VMware)公司的一套开源框架。 VMware Spring Boot 4.0.0至4.0.5版本、3.5.0至3.5.13版本、3.4.0至3.4.15版本、3.3.0至3.3.18版本和2.7.0至2.7.32版本存在安全漏洞,该漏洞源于可预测的临时目录和ApplicationTemp所有权验证问题,可能导致本地攻击者控制ApplicationTemp使用的目录,读取会话信息并劫持认证用户,或部署小工具链并以应用程序用户身份执行代码。
CVSS Information
N/A
Vulnerability Type
N/A