Impact
The vulnerability allows a partition interceptor to be improperly added while sending a message, which could lead to unintended message processing or potential data manipulation. This flaw stems from insufficient validation of interceptor configurations and could enable an attacker to influence message flows within the Spring Cloud Stream framework.
Affected Systems
Spring Cloud Stream versions 4.2.0 through 4.2.6, 4.3.0 through 4.3.3, and 5.0.0 through 5.0.2 are impacted. Users of these releases should verify the exact version installed and determine whether they fall within the affected ranges.
Risk and Exploitability
The CVSS score is 3.1, indicating a low severity. Although the EPSS score is not available, the vulnerability is not listed in CISA KEV, suggesting it has not been widely exploited yet. The likely attack vector would involve a malicious contributor or compromised component that can manipulate interceptor configuration during message dispatch. Given the low severity and lack of publicly known exploit activity, the risk is moderate, but organizations should still remediate promptly to eliminate the potential for unexpected message handling.
OpenCVE Enrichment