AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-22118

HIGH · CVSS 7.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-05-27 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. See the original NVD description below for full technical details.

CVE
CVE-2021-22118
Severity
HIGH
CVSS
7.8
EPSS
0.40%

Original NVD Description

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Related CVEs

Other vulnerabilities affecting the same vendor(s)