spring-integration-core is vulnerable to Information Disclosure
82
High Risk
spring-integration-core fluxTransform shares a RequestMessageHolder across concurrent messages. When the fluxFunction emits asynchronously, reply headers such as replyChannel, correlationId, and tenant headers can be copied from the newest upstream message. One user's payload can then be delivered on another user's reply channel. The patch isolates request headers per in-flight transformation.
You are affected if you are using a version that falls within the vulnerable range and an IntegrationFlow uses .fluxTransform() with an asynchronous fluxFunction that emits raw payloads.
spring-integration-core is vulnerable to Information Disclosure in versions 0.0.1 - 7.0.5 and 7.1.0 - 7.1.0.
Upgrade the org.springframework.integration:spring-integration-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant