CyberRota Analysis
AI-GeneratedThe PropertiesPersistingMetadataStore in affected versions of Spring Integration improperly sets world-readable permissions on the metadata store file located at ${java.io.tmpdir}/spring-integration/metadata-store.properties. This vulnerability could lead to unauthorized access to sensitive metadata, potentially exposing application state information to malicious actors. Organizations using the specified versions of Spring Integration should prioritize remediation to mitigate the risk of data exposure.
Original NVD Description
PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)