CVE-2021-22118: Improper Privilege Management
(updated )
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
References
- github.com/advisories/GHSA-gfwj-fwqj-fp3v
- nvd.nist.gov/vuln/detail/CVE-2021-22118
- security.netapp.com/advisory/ntap-20210713-0005/
- tanzu.vmware.com/security/cve-2021-22118
- www.oracle.com//security-alerts/cpujul2021.html
- www.oracle.com/security-alerts/cpuapr2022.html
- www.oracle.com/security-alerts/cpujan2022.html
- www.oracle.com/security-alerts/cpuoct2021.html
Detect and mitigate CVE-2021-22118 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →