CVE-2024-52302: Osamataher Java-Springboot-Codebase

High severity, CVSS 8.7. EPSS: 3.4% chance of exploitation in the next 30 days.

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).

Affected products

  • Osamataher Java-Springboot-Codebase: before 204402bb8b68030c14911379ddc82cfff00b8538 (fixed in 204402bb8b68030c14911379ddc82cfff00b8538)

Published 2024-11-14. Last modified 2026-06-17.