Intel

AIKIDO-2026-434308

spring-cloud-function-adapter-azure is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log FileCVE-2026-59301 Published 6 days ago

31

Low Risk

This Affects:

JAVAspring-cloud-function-adapter-azure
4.2.0 - 5.0.3
Fixed in 5.0.4
Are you affected? Scan for Free

TL;DR

spring-cloud-function-adapter-azure can write sensitive data to logs. Secrets or payload fields may then appear in Azure Monitor or application logs. Anyone with log access can recover that material. The patch redacts sensitive values before logging.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the Azure adapter logs request or credential material.

Background info

spring-cloud-function-adapter-azure is vulnerable to Insertion of Sensitive Information into Log File in versions 4.2.0 - 5.0.3.

How to fix this

Upgrade the org.springframework.cloud:spring-cloud-function-adapter-azure library to the patch version.