Bug 2487797 (CVE-2026-40987)
| Summary: | CVE-2026-40987 Spring Integration: Spring Integration: Arbitrary file write via malicious server | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anujha, asoldano, bbaranow, bmaxwell, bstansbe, dlofthou, gmalinko, istudens, ivassile, iweiss, janstey, mosmerov, msvehla, nwallace, pdelbell, pesilva, pjindal, pmackay, rstancel, rstepani, thjenkin, vdosoudi |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Spring Integration. A malicious or compromised FTP (File Transfer Protocol), SFTP (SSH File Transfer Protocol), or SMB (Server Message Block) server can exploit this vulnerability. This allows the server to write arbitrary files with attacker-controlled content to any location on the client's filesystem, bypassing the configured local directory restrictions. This could lead to unauthorized data modification or execution of malicious code on the client system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-06-11 07:01:22 UTC
|