Impact
A local unprivileged user can pre‑create a symbolic link named /tmp/ziptransformer that points to any directory the user has write access to. When Spring Integration starts, its Zip/UnZip transformer uses this predictable temporary directory to write extracted files. Because the symlink redirects the output path, the user can cause the application to create, overwrite, or delete files in arbitrary locations. This flaw can lead to data integrity violations, possible denial of service if critical process files are overwritten, and may provide a foothold for further local abuse.
Affected Systems
The vulnerability affects Spring Integration versions 7.1.0; 7.0.0 through 7.0.5; 6.5.0 through 6.5.10; and 6.4.0 through 6.4.12. The flaw is local in scope and requires an attacker to have a non‑privileged account on the same host where the application runs.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate risk severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not yet documented. The likely attack vector is local; an attacker must pre‑create the symlink before the application boots. If leveraged, the flaw permits arbitrary file writes, which could compromise data integrity or be a stepping‑stone to privilege escalation. The overall risk is therefore moderate but should be mitigated promptly by applying an available patch or equivalent workaround.
OpenCVE Enrichment