Vulnerability Details CVE-2024-37084
                In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.78
                        
                    
                    
                        
                            EPSS Ranking 99.0%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 9.8
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2024-37084
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:spring_cloud_data_flow:2.11.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:spring_cloud_data_flow:2.11.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:spring_cloud_data_flow:2.11.2