spring-integration-core is vulnerable to Incorrect Permission Assignment for Critical Resource
32
Low Risk
spring-integration-core PropertiesPersistingMetadataStore writes ${java.io.tmpdir}/spring-integration/metadata-store.properties without restricting permissions. On a typical POSIX host the file is world-readable in a shared temp directory. Other local users can read processed-message keys, offsets, or idempotency markers. The patch creates the store with owner-only permissions.
You are affected if you are using a version that falls within the vulnerable range and PropertiesPersistingMetadataStore is used on a multi-user host.
spring-integration-core is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.0.1 - 7.0.5 and 7.1.0 - 7.1.0.
Upgrade the org.springframework.integration:spring-integration-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant