CVE-2026-40987: Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization
Spring
·
2026-06-10
·
via Spring Security Advisories
Description A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client f…
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。