spring-boot is vulnerable to Insecure Temporary File
53
Medium Risk
Spring Boot's Artemis auto-configuration uses a predictable, static directory for embedded Artemis broker data when no custom data directory is configured. A local attacker with access to the same host can pre-create the directory or replace it with a symbolic link before application startup, potentially enabling unauthorized access to message queue data, message tampering, or further exploitation through malicious journal contents.
You are affected if using a vulnerable version.
spring-boot is vulnerable to Insecure Temporary File in versions 0.0.1 - 2.7.33, 3.0.0 - 3.3.19, 3.4.0 - 3.4.16, 3.5.0 - 3.5.14 and 4.0.0 - 4.0.6.
Upgrade the org.springframework.boot:spring-boot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant