Spring Boot
cpe:2.3:a:pivotal_software:spring_boot:*:*:*:*:*:*:*, +1 more
- >= 4.0.0, <= 4.0.5
- >= 3.5.0, <= 3.5.13
- >= 3.4.0, <= 3.4.15
- >= 3.3.0, <= 3.3.18
- >= 2.7.0, <= 2.7.32
A vulnerability exists in VMware Spring Boot versions 4.0.0 to 4.0.5, 3.5.0 to 3.5.13, 3.4.0 to 3.4.15, 3.3.0 to 3.3.18, and 2.7.0 to 2.7.32. When the 'server.servlet.session.persistent' setting is enabled, a local attacker on the same host as the application can exploit predictable ownership verification of the temporary directory used by 'ApplicationTemp'. This could lead to unauthorized access to session information, allowing the attacker to hijack authenticated users or execute code as the application's user by deploying a gadget chain.
Exploitation of this vulnerability could result in session hijacking of authenticated users and unauthorized code execution as the application's user.
Users should upgrade to Spring Boot 4.0.6, 3.5.14, 3.4.16 (Enterprise Support Only), 3.3.19 (Enterprise Support Only) or 2.7.33 (Enterprise Support Only).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.