{"id":"CVE-2022-27772","aliases":["GHSA-cm59-pr5q-cw85"],"url":"https://o3.security/vulnerability/CVE-2022-27772","summary":"Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot","details":"spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer supported by the maintainer","published":"2022-03-30T17:45:42Z","modified":"2026-07-15T01:48:56.395079704Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.boot:spring-boot","fixedVersion":"2.2.11.RELEASE"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27772.json"},{"type":"ADVISORY","url":"https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-cm59-pr5q-cw85"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-27772"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:56.395079704Z"}}