spring-integration-scripting is vulnerable to Race Condition
42
Medium Risk
spring-integration-scripting reuses one ScriptEngine for every message. Engines that are not thread-safe, such as Kotlin kts, can leak one message's bindings into another evaluation under concurrency. In a multi-tenant flow that is cross-request disclosure. The patch avoids sharing non-thread-safe engines across concurrent messages.
You are affected if you are using a version that falls within the vulnerable range and a script-backed channel reuses a JSR-223 ScriptEngine that reports THREADING=null.
spring-integration-scripting is vulnerable to Race Condition in versions 0.0.1 - 7.0.5 and 7.1.0 - 7.1.0.
Upgrade the org.springframework.integration:spring-integration-scripting library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant