CVE-2024-37084

CRITICAL

Vmware Spring Cloud Data Flow < 2.11.4 - Code Injection

Title source: rule

Description

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

Exploits (4)

nomisec WORKING POC 5 stars
by Ly4j · poc
https://github.com/Ly4j/CVE-2024-37084-Exp
nomisec WORKING POC 3 stars
by Kayiyan · poc
https://github.com/Kayiyan/CVE-2024-37084-Poc
nomisec STUB 2 stars
by vuhz · poc
https://github.com/vuhz/CVE-2024-37084

Scores

CVSS v3 9.8
EPSS 0.8330
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
org.springframework.cloud/spring-cloud-skipper 0 - 2.11.4Maven
vmware/spring_cloud_data_flow 2.11.0 - 2.11.4
Published Jul 25, 2024
Tracked Since Feb 18, 2026