From c6b66e4b27e3a87af84e028ed373dfa671448e9b Mon Sep 17 00:00:00 2001 From: oleg-andreev-check24 <165012101+oleg-andreev-check24@users.noreply.github.com> Date: Mon, 27 Jul 2026 11:38:49 +0200 Subject: [PATCH] Improve GHSA-792x-6vq6-j8r9 --- .../06/GHSA-792x-6vq6-j8r9/GHSA-792x-6vq6-j8r9.json | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2026/06/GHSA-792x-6vq6-j8r9/GHSA-792x-6vq6-j8r9.json b/advisories/github-reviewed/2026/06/GHSA-792x-6vq6-j8r9/GHSA-792x-6vq6-j8r9.json index 89ed078b13e07..62b18de977004 100644 --- a/advisories/github-reviewed/2026/06/GHSA-792x-6vq6-j8r9/GHSA-792x-6vq6-j8r9.json +++ b/advisories/github-reviewed/2026/06/GHSA-792x-6vq6-j8r9/GHSA-792x-6vq6-j8r9.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-792x-6vq6-j8r9", - "modified": "2026-07-24T20:35:04Z", + "modified": "2026-07-24T20:35:05Z", "published": "2026-06-11T09:31:55Z", "aliases": [ "CVE-2026-40987" ], "summary": "Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem", - "details": "A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.\n\nAffected versions:\nSpring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.", + "details": "Hello, can you please put as patched version 7.1.0 also osv scanner counts it as positive.", "severity": [ { "type": "CVSS_V3", @@ -28,11 +28,14 @@ "introduced": "7.0.0" }, { - "fixed": "7.0.5" + "fixed": "7.0.5, 7.1.0" } ] } - ] + ], + "database_specific": { + "last_known_affected_version_range": "< 7.0.5" + } }, { "package": {