Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40987

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.

A flaw was found in Spring Integration. A malicious or compromised FTP (File Transfer Protocol), SFTP (SSH File Transfer Protocol), or SMB (Server Message Block) server can exploit this vulnerability. This allows the server to write arbitrary files with attacker-controlled content to any location on the client's filesystem, bypassing the configured local directory restrictions. This could lead to unauthorized data modification or execution of malicious code on the client system.

Отчет

Red Hat ships Spring Integration as a bundled dependency in several middleware products. A flaw was found in Spring Integration's FTP, SFTP, and SMB inbound file synchronization adapters where server-supplied filenames are written to the local filesystem without path canonicalization, allowing a malicious or compromised remote server to write arbitrary files outside the configured local directory. Products shipping spring-integration-file, spring-integration-sftp, or spring-integration-ftp modules are directly exposed. Products bundling only spring-integration-core may not have the vulnerable code path but are included pending detailed analysis.

Меры по смягчению последствий

Restrict network access so that applications using Spring Integration file synchronization (FTP, SFTP, SMB inbound adapters) can only connect to trusted, known servers. Use firewall rules or network policies to prevent connections to untrusted endpoints. Additionally, run the application with minimal filesystem permissions to limit the impact of any arbitrary file write.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8spring-integration-coreNot affected
Red Hat Data Grid 8spring-integration-fileNot affected
Red Hat Data Grid 8spring-integration-sftpNot affected
Red Hat Fuse 7spring-integration-coreWill not fix
Red Hat Fuse 7spring-integration-httpWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packspring-integration-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packspring-integration-fileNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packspring-integration-sftpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2487797Spring Integration: Spring Integration: Arbitrary file write via malicious server

EPSS

Процентиль: 11%
0.0021
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
2 месяца назад

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.

CVSS3: 7.1
github
2 месяца назад

Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem

EPSS

Процентиль: 11%
0.0021
Низкий

7.1 High

CVSS3