GHSA-792x-6vq6-j8r9
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
Quick fix
GHSA-792x-6vq6-j8r9 — org.springframework.integration:spring-integration-file: upgrade to the fixed version with the command below.
# pom.xml: bump <version>7.0.5</version> for org.springframework.integration:spring-integration-file Details
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.
Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.
Are you affected?
Enter the version of the package you're using.
Affected packages
7.0.0 Fixed in: 7.0.5 # pom.xml: bump <version>7.0.5</version> for org.springframework.integration:spring-integration-file 6.5.0 No fixed version published yet for org.springframework.integration:spring-integration-file (maven). Pin to a known-safe version or switch to an alternative.
6.4.0 No fixed version published yet for org.springframework.integration:spring-integration-file (maven). Pin to a known-safe version or switch to an alternative.
6.3.0 No fixed version published yet for org.springframework.integration:spring-integration-file (maven). Pin to a known-safe version or switch to an alternative.
0 No fixed version published yet for org.springframework.integration:spring-integration-file (maven). Pin to a known-safe version or switch to an alternative.