spring-cloud-stream is vulnerable to Improper Access Control
31
Low Risk
spring-cloud-stream can attach a partition interceptor to the wrong send path. Messages may then be partitioned or observed by logic that should not run for that destination. A high-privilege sender with a specific send pattern can trigger the mis-wiring. The patch adds partition interceptors only to the intended channel.
You are affected if you are using a version that falls within the vulnerable range and partition interceptors are added while sending messages.
spring-cloud-stream is vulnerable to Improper Access Control in versions 4.2.0 - 5.0.2.
Upgrade the org.springframework.cloud:spring-cloud-stream library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant