Overview
About vulnerability
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating/tmp/ziptransformer as a symlink before the application starts. Extracted archive contents (and ZipTransformer output files) then land in the symlink target under the application’s uid, enabling local file planting or disclosure.
Details
- Affected product:
- Spring
- Affected packages:
- Spring Integration @ 6.4.9 (+570 more)