CVE-2024-37084
CRITICALSpring Cloud Data Flow < 2.11.4 - Authenticated Arbitrary File Write via Skipper Server API
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2024-37084. PoCs published by Ly4j, Kayiyan, vuhz.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-37084, leveraging YAML deserialization to achieve remote code execution (RCE) via a malicious JAR payload. The exploit involves uploading a crafted package to a vulnerable endpoint, triggering arbitrary command execution.
Description
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
Exploits (3)
This repository contains a functional exploit for CVE-2024-37084, leveraging YAML deserialization to achieve remote code execution (RCE) via a malicious JAR payload. The exploit involves uploading a crafted package to a vulnerable endpoint, triggering arbitrary command execution.
This repository contains a functional PoC for CVE-2024-37084, a remote code execution vulnerability in Spring Cloud. The exploit leverages YAML deserialization to execute arbitrary code by uploading a malicious package with a crafted payload URL.
The repository contains only a minimal README with a CVE title and no exploit code, technical details, or functional proof-of-concept. It lacks any meaningful content to demonstrate or analyze the vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H