CyberRota Analysis
AI-GeneratedA vulnerability exists in Spring Integration versions 6.4.0 to 7.1.0, where an attacker can manipulate the file_name header in a message processed by a ZipTransformer, leading to the creation of a .zip archive at an arbitrary filesystem location outside the designated workDirectory. This could result in unauthorized file access or overwriting critical files on the server. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks.
Original NVD Description
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Related CVEs
Other vulnerabilities affecting the same vendor(s)