GHSA-gfwj-fwqj-fp3v
GitHub Security Advisory
Improper Privilege Management in Spring Framework
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Affected Packages
Maven
org.springframework:spring-web
Affected versions:
5.2.0
(fixed in 5.2.15)
Maven
org.springframework:spring-web
Affected versions:
5.3.0
(fixed in 5.3.7)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 29, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.