Spring Cloud Contract vulnerable to local information disclosure
Low severity
GitHub Reviewed
Published
Jan 31, 2024
to the GitHub Advisory Database
•
Updated Jun 4, 2025
Package
Affected versions
= 4.1.0
>= 4.0.0, < 4.0.5
>= 3.1.0, < 3.1.10
Patched versions
4.1.1
4.0.5
3.1.10
Description
Published by the National Vulnerability Database
Jan 31, 2024
Published to the GitHub Advisory Database
Jan 31, 2024
Reviewed
Jan 31, 2024
Last updated
Jun 4, 2025
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency.
References