spring-integration-zip is vulnerable to Path Traversal
54
Medium Risk
spring-integration-zip ZipTransformer builds its work directory from the file_name header without sanitizing path elements. A producer who can set that header can write the resulting zip archive outside the configured workDirectory. Default ZipResultType.FILE is enough for this path. The patch sanitizes file_name before building the output path.
You are affected if you are using a version that falls within the vulnerable range and ZipTransformer runs with ZipResultType.FILE and a file_name header from untrusted messages.
spring-integration-zip is vulnerable to Path Traversal in versions 6.4.0 - 7.0.5 and 7.1.0 - 7.1.0.
Upgrade the org.springframework.integration:spring-integration-zip library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant