CVE 5.3 MEDIUM

Predictable Temp Directory in Artemis Auto-configuration_CVE-2026-41001

5.3 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Description

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application starts.

Affected versions:
Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16; 3.3.0 through 3.3.19; 2.7.0 through 2.7.33.

Basic Information

ID CVE-2026-41001
Source vmware
Published Jun 11, 2026 at 05:04

Affected Product

Vendor Spring
Product Spring Boot
Version 4.0.0
Affected Versions Spring Spring Boot 4.0.0
Spring Spring Boot 3.5.0
Spring Spring Boot 3.4.0
Spring Spring Boot 3.3.0
Spring Spring Boot 2.7.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.