Spring Cloud Contract vulnerable to local information disclosure
Low severity
GitHub Reviewed
Published
Jan 31, 2024
to the GitHub Advisory Database
•
Updated Feb 9, 2024
Package
Affected versions
= 4.1.0
>= 4.0.0, < 4.0.5
>= 3.1.0, < 3.1.10
Patched versions
4.1.1
4.0.5
3.1.10
Description
Published by the National Vulnerability Database
Jan 31, 2024
Published to the GitHub Advisory Database
Jan 31, 2024
Reviewed
Jan 31, 2024
Last updated
Feb 9, 2024
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency.
References