spring-cloud-function-context is vulnerable to Path Traversal
20
Low Risk
spring-cloud-function-context can treat an untrusted location as a local file or remote URL. That may allow arbitrary file reads and server-side request forgery. Exploitation needs a high-privilege caller and user interaction according to the vendor scoring. The patch restricts resource locations used during function lookup.
You are affected if you are using a version that falls within the vulnerable range and Spring Cloud Function resource lookup is reachable with untrusted location input.
spring-cloud-function-context is vulnerable to Path Traversal in versions 4.2.0 - 5.0.3.
Upgrade the org.springframework.cloud:spring-cloud-function-context library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant