← Back

Spring Cloud Data Flow

spring_cloud_data_flow

Vendor: Vmware • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
1Spring Cloud Data Flow
Jun 17, 2026
Jul 25, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could le...Show more
In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the serverShow less
1Vmware
1Spring Cloud Data Flow
Jun 17, 2026
Jan 27, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.