CVE-2026-59311
6.8
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Summary
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Integration | 7.1.0 | affected |
| Spring | Spring Integration | 7.0.0 <= 7.0.5 | affected |
| Spring | Spring Integration | 6.5.0 <= 6.5.10 | affected |
| Spring | Spring Integration | 6.4.0 <= 6.4.12 | affected |
Weaknesses
- CWE-59 Improper Link Resolution Before File Access ('Link Following')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.