spring-cloud-config-server is vulnerable to Authorization Bypass Through User-Controlled Key
75
High Risk
Affected versions of spring-cloud-config-server using Google Secrets Manager as a backend allow a client to craft requests that may expose secrets from unintended GCP projects accessible by the Config Server. The issue occurs because project access is not sufficiently restricted when resolving secrets, potentially allowing unauthorized cross-project secret access.
You are affected if you are using a version that falls within the vulnerable range and you are using Google Secrets Manager.
spring-cloud-config-server is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.1 - 3.1.13, 4.0.0 - 4.1.9, 4.2.0 - 4.2.6, 4.3.0 - 4.3.2 and 5.0.0 - 5.0.2.
Upgrade the org.springframework.cloud:spring-cloud-config-server library to a patch version or set spring.cloud.config.server.gcp-secret-manager.token-mandatory=true.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant