CVE-2026-59284
6.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L
Summary
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Cloud Commons | 5.0.0 <= 5.0.2 | affected |
| Spring | Spring Cloud Commons | 4.3.0 <= 4.3.3 | affected |
| Spring | Spring Cloud Commons | 4.0.0 <= 4.2.6 | affected |
| Spring | Spring Cloud Commons | 0 <= 3.1.10 | affected |
Weaknesses
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.