Loading HuntDB...

GHSA-gfwj-fwqj-fp3v

GitHub Security Advisory

Improper Privilege Management in Spring Framework

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Affected Packages

Maven org.springframework:spring-web
Affected versions: 5.2.0 (fixed in 5.2.15)
Maven org.springframework:spring-web
Affected versions: 5.3.0 (fixed in 5.3.7)

Related CVEs

Key Information

GHSA ID
GHSA-gfwj-fwqj-fp3v
Published
May 24, 2022 7:03 PM
Last Modified
July 19, 2023 2:39 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.springframework:spring-web
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 29, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.