CVE-2024-37084 is a critical arbitrary file write vulnerability affecting Spring Cloud Data Flow versions prior to 2.11.4. A malicious user with API access to the Skipper server can craft an upload request to write files to any location on the server, potentially leading to a full compromise. This vulnerability carries a high CVSS score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating it can be exploited remotely with low privileges and complexity, resulting in high impact to confidentiality, integrity, and availability. While not yet in the KEV catalog and lacking public exploit code in Metasploit or Nuclei, its high EPSS score of 0.83304 and significant community discussion suggest a strong likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.11.0, < 2.11.4CPE matchmatch criteria | cpe:2.3:a:vmware:spring_cloud_data_flow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.