Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn Spring Cloud Contract, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency.
Spring Cloud Contract:
| Fix version | Availability |
|---|---|
| 4.1.1 | OSS |
| 4.0.5 | OSS |
| 3.1.10 | OSS |
No further mitigation steps are necessary.
This issue was identified and responsibly reported by Michael Kimball from Oddball.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy