CVE-2021-22118
published 2021-05-27CVE-2021-22118: In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
32.0th percentile
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | communications_brm_elastic_charging_engine | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| oracle | communications_diameter_intelligence_hub | 8.0.0 – 8.1.0 | — |
| oracle | communications_diameter_intelligence_hub | 8.2.0 – 8.2.3 | — |
| oracle | communications_element_manager | 8.2.0 – 8.2.4.0 | — |
| oracle | communications_interactive_session_recorder | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_session_report_manager | 8.0.0 – 8.2.4.0 | — |
| oracle | communications_session_route_manager | 8.0.0 – 8.2.4.0 | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | documaker | 12.6.0 – 12.6.4 | — |
| oracle | enterprise_data_quality | — | — |
| oracle | enterprise_data_quality | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.8 – 8.1.1 | — |
| oracle | healthcare_data_repository | — | — |
| oracle | insurance_policy_administration | 11.0 – 11.3.1 | — |
| oracle | insurance_rules_palette | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Other (Spring Framework) — CVE-2021-22118
vendor_oracle·2022-07-15·CVSS 7.8
CVE-2021-22118 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Other (Spring Framework) — CVE-2021-22118
Oracle Oracle Retail Applications Risk Matrix: Other (Spring Framework) vulnerability
CVE: CVE-2021-22118
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Spring Framework) — CVE-2021-22118
vendor_oracle·2022-04-15·CVSS 7.8
CVE-2021-22118 [HIGH] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Spring Framework) — CVE-2021-22118
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Spring Framework) vulnerability
CVE: CVE-2021-22118
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: TMF API (Spring Framework) — CVE-2021-22118
vendor_oracle·2022-01-15·CVSS 7.8
CVE-2021-22118 [HIGH] Oracle Oracle Communications Applications Risk Matrix: TMF API (Spring Framework) — CVE-2021-22118
Oracle Oracle Communications Applications Risk Matrix: TMF API (Spring Framework) vulnerability
CVE: CVE-2021-22118
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Controller (Spring Framework) — CVE-2021-22118
vendor_oracle·2021-10-15·CVSS 7.8
CVE-2021-22118 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Controller (Spring Framework) — CVE-2021-22118
Oracle Oracle Communications Applications Risk Matrix: Controller (Spring Framework) vulnerability
CVE: CVE-2021-22118
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Retail Applications Risk Matrix: PeopleSoft Integration Bugs (Spring Framework) — CVE-2021-22118
vendor_oracle·2021-07-15·CVSS 7.8
CVE-2021-22118 [HIGH] Oracle Oracle Retail Applications Risk Matrix: PeopleSoft Integration Bugs (Spring Framework) — CVE-2021-22118
Oracle Oracle Retail Applications Risk Matrix: PeopleSoft Integration Bugs (Spring Framework) vulnerability
CVE: CVE-2021-22118
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Red Hat
spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux application
vendor_redhat·2021-05-25·CVSS 7.8
CVE-2021-22118 [HIGH] CWE-281 spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux application
spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux application
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Statement: In OpenShift Container Platform (OCP) the jenkins package bundles the vulnerable version of spring-framework, but as Jenkins is not a type of WebFlux application is not impacted by this vulnerability. Therefore the OCP components have been marked as affected/wontfix. This may be fixed in a
Debian
CVE-2021-22118: libspring-java - In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to ...
vendor_debian·2021·CVSS 7.8
CVE-2021-22118 [HIGH] CVE-2021-22118: libspring-java - In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to ...
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Improper Privilege Management in Spring Framework
osv·2022-05-24
CVE-2021-22118 [HIGH] Improper Privilege Management in Spring Framework
Improper Privilege Management in Spring Framework
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
GHSA
Improper Privilege Management in Spring Framework
ghsa·2022-05-24
CVE-2021-22118 [HIGH] CWE-269 Improper Privilege Management in Spring Framework
Improper Privilege Management in Spring Framework
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
OSV
CVE-2021-22118: In Spring Framework, versions 5
osv·2021-05-27·CVSS 7.8
CVE-2021-22118 [HIGH] CVE-2021-22118: In Spring Framework, versions 5
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
No detection rules found.
No public exploits indexed.
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2021-22118 spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux application
bugzilla·2021-06-22·CVSS 7.8
CVE-2021-22118 [HIGH] CVE-2021-22118 spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux application
CVE-2021-22118 spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux application
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
References:
https://github.com/spring-projects/spring-framework/issues/26931
Discussion:
Upstream fix:
https://github.com/spring-projects/spring-framework/commit/cce60c479c22101f24b2b4abebb6d79440b120d1
---
Marking Red Hat Integration Camel K as having a low impact, this is because
https://security.netapp.com/advisory/ntap-20210713-0005/https://tanzu.vmware.com/security/cve-2021-22118https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://security.netapp.com/advisory/ntap-20210713-0005/https://tanzu.vmware.com/security/cve-2021-22118https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-05-27
Published