Overview
About vulnerability
Unless the application explicitly raisessmbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM.
An on-path attacker can downgrade the dialect, intercept or alter files moved by the SMB adapters, or capture NTLM credentials.
Details
- Affected product:
- Spring
- Affected packages:
- Spring Integration @ 6.4.10 (+570 more)