QID 981414
QID 981414: Java (maven) Security Update for org.springframework.integration:spring-integration-zip (GHSA-m9jm-rhrm-gcxj)
Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m9jm-rhrm-gcxj for updates pertaining to this vulnerability.
Vendor References
- GHSA-m9jm-rhrm-gcxj -
github.com/advisories/GHSA-m9jm-rhrm-gcxj
CVEs related to QID 981414
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m9jm-rhrm-gcxj | org.springframework.integration:spring-integration-zip |
|