Impact
PropertiesPersistingMetadataStore, the default file‑based metadata store in Spring Integration, writes its state to a file named metadata‑store.properties in the temporary directory (${java.io.tmpdir}/spring‑integration). The file is created with world‑readable permissions, allowing any user or process on the affected host to read the contents. This represents an information disclosure vulnerability flagged as CWE‑200.
Affected Systems
Spring Integration distributed by Spring. The vulnerability affects the following released versions: 7.1.0; 7.0.0 through 7.0.5; 6.5.0 through 6.5.10; 6.4.0 through 6.4.12; and 5.5.21 and all earlier releases.
Risk and Exploitability
The CVSS base score of 3.2 indicates low severity, and EPSS data is not available, suggesting no recent exploitation reports. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local file read by any user with access to the host’s temporary directory, implying that systems exposed to multi‑user contexts or with inadequate file permissions are at risk.
OpenCVE Enrichment