Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41001

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 5.3

Описание

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.

A flaw was found in Spring Boot. The ArtemisEmbeddedConfigurationFactory component uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can exploit this by pre-creating this predictable directory or placing a symlink before the application starts. This could allow the attacker to manipulate the data directory, potentially leading to information disclosure, data modification, or denial of service.

Отчет

A flaw was found in Spring Boot. The embedded ActiveMQ Artemis broker uses a fixed, predictable path as the default data directory. A local attacker with access to the host can pre-create this directory to hijack message queue data, inject malicious messages, or potentially execute code via deserialization. Exploitation requires local access, use of the embedded Artemis broker (not external), and no custom data directory configured. Red Hat products using external message brokers or not using Artemis at all are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Clientsspring-bootFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-bootFix deferred
Red Hat Data Grid 8spring-bootFix deferred
Red Hat Enterprise Linux 8log4j:2/log4jFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packspring-bootFix deferred
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Not affected
Red Hat Single Sign-On 7spring-bootFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1188
https://bugzilla.redhat.com/show_bug.cgi?id=2487805spring-boot: Spring Boot: Local attacker can manipulate data directory due to predictable path

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
2 месяца назад

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.

CVSS3: 5.3
github
2 месяца назад

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.

5.3 Medium

CVSS3