CyberRota Analysis
AI-GeneratedThe Spring Cloud Config Server is vulnerable to time-of-check-time-of-use (TOCTOU) attacks due to improper handling of the base directory used for cloning SVN repositories. This vulnerability could allow an attacker to manipulate files in the directory before they are accessed, potentially leading to unauthorized access or code execution. Organizations using affected versions of Spring Cloud Config should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)