CVE-2024-37084

CRITICAL

Spring Cloud Data Flow < 2.11.4 - Authenticated Arbitrary File Write via Skipper Server API

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2024-37084. PoCs published by Ly4j, Kayiyan, vuhz.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-37084, leveraging YAML deserialization to achieve remote code execution (RCE) via a malicious JAR payload. The exploit involves uploading a crafted package to a vulnerable endpoint, triggering arbitrary command execution.

Description

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

Exploits (3)

nomisec WORKING POC 5 stars
by Ly4j · poc
https://github.com/Ly4j/CVE-2024-37084-Exp

This repository contains a functional exploit for CVE-2024-37084, leveraging YAML deserialization to achieve remote code execution (RCE) via a malicious JAR payload. The exploit involves uploading a crafted package to a vulnerable endpoint, triggering arbitrary command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Unknown (likely a Java-based application with YAML parsing vulnerabilities)
No auth needed
Prerequisites: Access to a vulnerable endpoint · Ability to host a malicious JAR file
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 3 stars
by Kayiyan · poc
https://github.com/Kayiyan/CVE-2024-37084-Poc

This repository contains a functional PoC for CVE-2024-37084, a remote code execution vulnerability in Spring Cloud. The exploit leverages YAML deserialization to execute arbitrary code by uploading a malicious package with a crafted payload URL.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Spring Cloud (version not specified)
No auth needed
Prerequisites: Target URL with vulnerable endpoint · Accessible payload URL hosting malicious JAR
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec STUB 2 stars
by vuhz · poc
https://github.com/vuhz/CVE-2024-37084

The repository contains only a minimal README with a CVE title and no exploit code, technical details, or functional proof-of-concept. It lacks any meaningful content to demonstrate or analyze the vulnerability.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Spring Cloud (version unspecified)
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.8330
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
org.springframework.cloud/spring-cloud-skipper 0 - 2.11.4Maven
vmware/spring_cloud_data_flow 2.11.0 - 2.11.4
Published Jul 25, 2024
Tracked Since Feb 18, 2026