← Back

CVE-2026-59311

nvd nist
Published: Aug 27, 2026Modified: Aug 31, 2026

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.6 / Impact: 5.2
Source: security@vmware.com (Secondary)

Description

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

Affected (8)

1 product
Spring Integration
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 6.4.0 to 6.4.12
From 6.5.0 to 6.5.10
From 7.0.0 to 7.0.5
Version 7.1.0
Version 7.1.0 milestone1
Version 7.1.0 milestone2
Version 7.1.0 milestone3
Version 7.1.0 rc1

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.