CyberRota Analysis
AI-GeneratedA local unprivileged user can exploit a symlink vulnerability in Spring Integration versions 6.4.0 to 7.1.0, allowing them to redirect Zip/UnZip transformer output to a directory of their choice. This could lead to unauthorized data exposure or manipulation. Organizations using affected versions should prioritize patching to mitigate potential risks associated with this vulnerability.
Original NVD Description
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Related CVEs
Other vulnerabilities affecting the same vendor(s)