CVE-2024-37084: VMware Spring Cloud Data Flow

High severity, CVSS 8.8. EPSS: 35.2% chance of exploitation in the next 30 days.

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

Affected products

  • VMware Spring Cloud Data Flow: from 2.11.0, before 2.11.4 (fixed in 2.11.4)

Published 2024-07-25. Last modified 2026-06-17.