CVE-2024-52302
CVSS V2 None
CVSS V3 None
Description
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).
Overview
- CVE ID
- CVE-2024-52302
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-11-14T15:26:49.407Z
- Last Modified Date
- 2024-11-14T15:57:49.416Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/OsamaTaher/Java-springboot-codebase/security/advisories/GHSA-rhcq-44g3-5xcx | x_refsource_CONFIRM |
https://github.com/OsamaTaher/Java-springboot-codebase/commit/204402bb8b68030c14911379ddc82cfff00b8538 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-52302 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52302 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-11-15 13:32:32 | Added to TrackCVE |