Summary
VMware security updates address a vulnerability in Spring Cloud Data Flow, a microservices-based streaming and batch data processing platform deployed on Cloud Foundry and Kubernetes.
This vulnerability could allow arbitrary files to be written to any file system path on affected systems.
Risk
Vulnerability community impact estimate: MEDIUM/YELLOW (62.3/100)1.
Type
- Remote Code Execution
Affected products and versions
Spring Cloud Data Flow 2.11.x, versions prior to 2.11.4
Mitigation actions
In line with vendor statements, it is recommended to update vulnerable products following the instructions in the security bulletin reported in the References section.
Unique Vulnerability Identifiers
References
https://spring.io/security/cve-2024-37084
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.