Overview
About vulnerability
Spring Boot’s ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker’s data directory when no explicit path is configured.
A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts. This enables the attacker to hijack message queue data, inject malicious messages, or potentially execute code via deserialization attacks through the journal.
Details
- Affected product:
- Apache CXF , Apache Log4j , Spring , amqp-10-jms-spring-boot , artemis , camel , grails-core , grails-data-mapping , grails-gsp , grails-plugin-converters
- Affected packages:
- Spring Boot @ 2.7.18 (+4824 more)