spring-integration-smb is vulnerable to Selection of Less-Secure Algorithm During Negotiation
66
Medium Risk
spring-integration-smb defaults the minimum SMB dialect to SMB1. The client can then negotiate a protocol without mandatory signing or encryption. An on-path attacker can downgrade the dialect, tamper with files, or capture NTLM credentials. The patch raises the default minimum dialect above SMB1.
You are affected if you are using a version that falls within the vulnerable range and SMB adapters are used without raising smbMinVersion above SMB1.
spring-integration-smb is vulnerable to Selection of Less-Secure Algorithm During Negotiation in versions 6.4.0 - 7.0.5 and 7.1.0 - 7.1.0.
Upgrade the org.springframework.integration:spring-integration-smb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant