spring-integration-file is vulnerable to Path Traversal
80
High Risk
Spring Integration contains a path traversal vulnerability in its remote file synchronization components. A malicious or compromised FTP, SFTP, or SMB server can provide crafted filenames that are written to the client filesystem without proper path canonicalization. This may allow files to be created or overwritten outside the configured local directory, potentially leading to unauthorized file modification, data corruption, or execution of attacker-controlled content.
You are affected if you are using a version that falls within the vulnerable range.
spring-integration-file is vulnerable to Path Traversal in versions 0.0.1 - 5.5.20, 6.0.0 - 6.3.14, 6.4.0 - 6.4.11, 6.5.0 - 6.5.8 and 7.0.0 - 7.0.4.
Upgrade the org.springframework.integration:spring-integration-file library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant