【中危】Steeltoe.Management.Endpoint 安全更新(GHSA-227r-jm2g-7cp4)
安全情报快照 · 风险级别:中危 · CVSS:6.5 · CVE-2026-50201 · GHSA-227r-jm2g-7cp4
先看结论
Steeltoe.Management.Endpoint存在安全风险,<= 4.1.0 受影响,建议升级至 4.2.0。
影响范围
| 生态 | 组件 | 受影响版本 | 首个修复版本 |
|---|---|---|---|
| nuget | Steeltoe.Management.Endpoint |
<= 4.1.0 | 4.2.0 |
| nuget | Steeltoe.Management.EndpointBase |
<= 3.3.0 | 3.4.0 |
处置建议
优先将 Steeltoe.Management.Endpoint 升级至 4.2.0 或更高版本;升级前请结合业务依赖完成兼容性验证。
上游技术详情(原文)
Summary
All Steeltoe actuator endpoints default to EndpointPermissions.Restricted, which is mapped to Cloud Foundry's read_basic_data permission (granted to Space Auditors and similar low-trust roles). Sensitive actuators including heap dump, environment, and thread dump do not raise this to EndpointPermissions.Full, so CF's read_sensitive_data permission flag is not enforced for those endpoints. Spring Boot's equivalent Cloud Foundry integration gates these endpoints with read_sensitive_data by default.
Impact
Any CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's read_sensitive_data permission, which is specifically designed to gate this access, has no effect.
Affected configuration
- Application is deployed on Cloud Foundry with CF actuator and security middleware active (added automatically by
AddAllActuators()when a CF environment is detected). - The attacker holds a CF role that grants
read_basic_data: Space Auditor, Space Manager, or Org Auditor.
Mitigations
If an immediate upgrade is not possible:
- Explicitly set
RequiredPermissions = EndpointPermissions.Fullin the options forHeapDumpEndpointOptions,EnvironmentEndpointOptions, andThreadDumpEndpointOptions. - If heap dump, thread dump, or environment are not needed in production, register only the required actuators individually instead of using
AddAllActuators().
来源与许可
- GitHub Advisory GHSA-227r-jm2g-7cp4
- https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-227r-jm2g-7cp4
- https://nvd.nist.gov/vuln/detail/CVE-2026-50201
- https://github.com/SteeltoeOSS/Steeltoe/commit/b39defa4db5f44f8696c456866b3a5b900d8d96b
- https://github.com/SteeltoeOSS/Steeltoe/commit/da6c604decd992f61aeef763f5814102dcb088c7
本页自动同步 GitHub Advisory Database 的公开数据,并保留上游原文供核验;不宣称原创分析。数据许可:CC-BY-4.0。
评论
登录 后参与讨论。
还没有评论,来说两句。