6.8
CVE-2026-59311
- EPSS 0.34%
- Veröffentlicht 27.08.2026 18:04:40
- Zuletzt bearbeitet 31.08.2026 18:06:13
- Erkennungen
Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Integration Version >= 6.4.0 <= 6.4.12
VMware ≫ Spring Integration Version >= 6.5.0 <= 6.5.10
VMware ≫ Spring Integration Version >= 7.0.0 <= 7.0.5
VMware ≫ Spring Integration Version 7.1.0 Update -
VMware ≫ Spring Integration Version 7.1.0 Update milestone1
VMware ≫ Spring Integration Version 7.1.0 Update milestone2
VMware ≫ Spring Integration Version 7.1.0 Update milestone3
VMware ≫ Spring Integration Version 7.1.0 Update rc1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.269 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 6.8 | 1.6 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
https://spring.io/security/cve-2026-59311