spring-cloud-config-server is vulnerable to Race Condition (TOCTOU)
72
High Risk
The base directory (spring.cloud.config.server.git.basedir) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.
You are affected if you are using a version that falls within the vulnerable range.
spring-cloud-config-server is vulnerable to Race Condition (TOCTOU) in versions 0.0.1 - 3.1.13, 4.0.0 - 4.1.9, 4.2.0 - 4.2.6, 4.3.0 - 4.3.2 and 5.0.0 - 5.0.2.
Upgrade the org.springframework.cloud:spring-cloud-config-server library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant