Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-50201

Опубликовано: 17 июн. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to EndpointPermissions.Restricted, which is mappeds to Cloud Foundry's read_basic_data permission (granted to Space Auditors and similar low-trust roles). Sensitive actuators including heap dump, environment, and thread dump do not raise this to EndpointPermissions.Full, so CF's read_sensitive_data permission flag is not enforced for those endpoints. Spring Boot's equivalent Cloud Foundry integration gates these endpoints with read_sensitive_data by default. Steeltoe.Management.Endpoint 4.2.0 and Steeltoe.Management.EndpointCore 3.4.0 patch the issue. If an immediate upgrade is not possible, explicitly set RequiredPermissions = EndpointPermissions.Full in the options for HeapDumpEndpointOptions,

EPSS

Процентиль: 14%
0.00231
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.5
github
29 дней назад

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

EPSS

Процентиль: 14%
0.00231
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269