Privilege Escalation Affecting org.springframework:spring-web package, versions [5.3.0,5.3.7) [5.0.0.RELEASE,5.2.15.RELEASE)


Severity

0.0
medium
0
10

    Threat Intelligence

    EPSS
    0.05% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGSPRINGFRAMEWORK-1296829
  • published 26 May 2021
  • disclosed 26 May 2021
  • credit Trung Pham of Viettel Cyber Security

How to fix?

Upgrade org.springframework:spring-web to version 5.3.7, 5.2.15.RELEASE or higher.

Overview

org.springframework:spring-web is a package that provides a comprehensive programming and configuration model for modern Java-based enterprise applications - on any kind of deployment platform.

Affected versions of this package are vulnerable to Privilege Escalation. By recreating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS Scores

version 3.1
Expand this section

Snyk

4.4 medium
  • Attack Vector (AV)
    Local
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    Low
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    Low
  • Integrity (I)
    Low
  • Availability (A)
    None
Expand this section

NVD

7.8 high
Expand this section

Red Hat

7.1 high