Spring Data Geode Insecure Temporary Directory Vulnerability Allowing Cache Data Exposure

Vulnerability

A vulnerability in Spring Data Geode allows for the extraction of snapshot archives into predictable and permissive directories within the system's temporary location. This issue is present in Spring Data Geode versions 2.0.0 prior to 2.7.18 and versions 1.7.0 through 2.2.13. On shared hosting environments, a local user with basic privileges could access another user's extracted snapshot contents, leading to unintended exposure of cache data.

Impact

Exploitation of this vulnerability could result in unauthorized access to another user's cache data on shared hosts.

Remediation

Users can upgrade to the Never-Ending Support (NES) version for Spring, available through HeroDevs, to address this vulnerability.

Added: Feb 19, 2026, 7:45 PM
Updated: Feb 19, 2026, 7:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.7
exploitability
2.6
remediation
0.0
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.