QID 981414

QID 981414: Java (maven) Security Update for org.springframework.integration:spring-integration-zip (GHSA-m9jm-rhrm-gcxj)

Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.7 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to GHSA-m9jm-rhrm-gcxj for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981414

    Software Advisories
    Advisory ID Software Component Link
    GHSA-m9jm-rhrm-gcxj org.springframework.integration:spring-integration-zip URL Logo github.com/advisories/GHSA-m9jm-rhrm-gcxj