Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request can lead to remote code execution.
Spring Cloud Data Flow:
| Fix version | Availability |
|---|---|
| 2.11.3 | OSS |
No further mitigation steps are necessary.
The issue was identified and responsibly reported by cokeBeer, crisprss, LFYSec, skyxsecurity.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy