Описание
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts.
Affected versions:
Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
A flaw was found in Spring Boot. The ArtemisEmbeddedConfigurationFactory component uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can exploit this by pre-creating this predictable directory or placing a symlink before the application starts. This could allow the attacker to manipulate the data directory, potentially leading to information disclosure, data modification, or denial of service.
Отчет
A flaw was found in Spring Boot. The embedded ActiveMQ Artemis broker uses a fixed, predictable path as the default data directory. A local attacker with access to the host can pre-create this directory to hijack message queue data, inject malicious messages, or potentially execute code via deserialization. Exploitation requires local access, use of the embedded Artemis broker (not external), and no custom data directory configured. Red Hat products using external message brokers or not using Artemis at all are not affected.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Clients | spring-boot | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-boot | Fix deferred | ||
| Red Hat Data Grid 8 | spring-boot | Fix deferred | ||
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-boot | Fix deferred | ||
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Not affected | ||
| Red Hat Single Sign-On 7 | spring-boot | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.
5.3 Medium
CVSS3