CyberRota Analysis
AI-GeneratedSpring Integration versions 5.5.21 and earlier, as well as 6.4.0 to 7.1.0, are vulnerable to manipulation of JMS properties by any producer publishing to a JMS destination. This allows attackers to inject arbitrary values into the Spring Integration MessageHeaders, potentially leading to unauthorized access or message processing issues. Organizations using these versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)