spring-cloud-config-server is vulnerable to Race Condition (TOCTOU)
72
High Risk
spring-cloud-config-server clones SVN repositories into spring.cloud.config.server.svn.basedir without protecting that directory against a time-of-check time-of-use race. A local high-privilege attacker can replace or redirect the base directory between the check and the clone. That can cause the server to read or write repository content outside the intended location. The patch closes the TOCTOU window around the SVN working directory.
You are affected if you are using a version that falls within the vulnerable range and the Config Server clones SVN repositories using spring.cloud.config.server.svn.basedir.
spring-cloud-config-server is vulnerable to Race Condition (TOCTOU) in versions 0.0.1 - 5.0.4.
Upgrade the org.springframework.cloud:spring-cloud-config-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant