Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreWhen using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 3.1.x | 3.1.14 | Enterprise Support Only |
| 4.1.x | 4.1.10 | Enterprise Support Only |
| 4.2.x | 4.2.7 | Enterprise Support Only |
| 4.3.x | 4.3.3 | OSS |
| 5.0.x | 5.0.3 | OSS |
If you cannot upgrade to one of the above releases you can set spring.cloud.config.server.gcp-secret-manager.token-mandatory=true to require the client to send a valid token that is then verified to have access to the secrets in the requested project.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy