Описание
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.
Affected versions:
Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.
A flaw was found in Spring Integration. A malicious or compromised FTP (File Transfer Protocol), SFTP (SSH File Transfer Protocol), or SMB (Server Message Block) server can exploit this vulnerability. This allows the server to write arbitrary files with attacker-controlled content to any location on the client's filesystem, bypassing the configured local directory restrictions. This could lead to unauthorized data modification or execution of malicious code on the client system.
Отчет
Red Hat ships Spring Integration as a bundled dependency in several middleware products. A flaw was found in Spring Integration's FTP, SFTP, and SMB inbound file synchronization adapters where server-supplied filenames are written to the local filesystem without path canonicalization, allowing a malicious or compromised remote server to write arbitrary files outside the configured local directory. Products shipping spring-integration-file, spring-integration-sftp, or spring-integration-ftp modules are directly exposed. Products bundling only spring-integration-core may not have the vulnerable code path but are included pending detailed analysis.
Меры по смягчению последствий
Restrict network access so that applications using Spring Integration file synchronization (FTP, SFTP, SMB inbound adapters) can only connect to trusted, known servers. Use firewall rules or network policies to prevent connections to untrusted endpoints. Additionally, run the application with minimal filesystem permissions to limit the impact of any arbitrary file write.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Data Grid 8 | spring-integration-core | Not affected | ||
| Red Hat Data Grid 8 | spring-integration-file | Not affected | ||
| Red Hat Data Grid 8 | spring-integration-sftp | Not affected | ||
| Red Hat Fuse 7 | spring-integration-core | Will not fix | ||
| Red Hat Fuse 7 | spring-integration-http | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-integration-core | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-integration-file | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-integration-sftp | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
EPSS
7.1 High
CVSS3