Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreWhen using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config:
| Fix version | Availability |
|---|---|
| 5.0.3 | OSS |
| 4.3.3 | OSS |
| 4.2.7 | Enterprise Support Only |
| 4.1.10 | Enterprise Support Only |
| 3.1.14 | Enterprise Support Only |
If you cannot upgrade to one of the above releases you can set spring.cloud.config.server.gcp-secret-manager.token-mandatory=true to require the client to send a valid token that is then verified to have access to the secrets in the requested project.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy