In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22118.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0"
}
]
},
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.1.0"
}
]
},
{
"events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.3"
}
]
},
{
"events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3.6"
}
]
},
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4.0"
}
]
},
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.5.0"
}
]
},
{
"events": [
{
"introduced": "12.6.0"
},
{
"last_affected": "12.6.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "8.0.8"
},
{
"last_affected": "8.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.0"
}
]
},
{
"events": [
{
"introduced": "11.0"
},
{
"last_affected": "11.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.2.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0"
}
]
},
{
"events": [
{
"introduced": "16.0"
},
{
"last_affected": "19.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0.0.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0.0.2.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0.0.3.1"
}
]
}
]