Spring Vulnerabilities Open Door to Arbitrary File Access and GCP Secret Leaks
ID: e5333238-b7af-5775-8f18-d409f95f9741
STIX ID: report--e5333238-b7af-5775-8f18-d409f95f9741
Feed Name: GBHackers
### Executive summary Security researchers disclosed four vulnerabilities in Spring Cloud Config Server — a critical directory traversal (CVE-2026-40982) enabling unauthenticated arbitrary file access, a high-severity GCP Secret Manager exposure (CVE-2026-40981) that can leak secrets across projects, a TOCTOU race condition affecting Git clone base directories (CVE-2026-41002), and a medium-severity logging issue that can write sensitive data to logs (CVE-2026-41004). Affected branches include 3.1.x, 4.1.x, 4.2.x, 4.3.x, and 5.0.x; patches and mitigation flags are provided for supported releases while older branches require VMware Enterprise Support to obtain fixes. Administrators are advised to apply the listed updates (e.g., 4.3.3, 5.0.3, 3.1.14, 4.1.10, 4.2.7) or enable the recommended configuration mitigations immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
