SteeltoeOSS Steeltoe.Security.Authentication.CloudFoundryBase是SteeltoeOSS的一个安全认证框架组件。 Steeltoe.Security.Authentication.CloudFoundryBase 3.4.0之前版本、Steeltoe.Security.Authentication.JwtBearer 4.2.0之前版本和Steeltoe.Security.Authentication.OpenIdConnect 4.2.0之前版本
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SteeltoeOSS | Steeltoe.Security.Authentication.CloudFoundryBase | < 3.4.0 |
affected |
| SteeltoeOSS | Steeltoe.Security.Authentication.JwtBearer | < 4.2.0 |
affected |
| SteeltoeOSS | Steeltoe.Security.Authentication.OpenIdConnect | < 4.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SteeltoeOSS | Steeltoe.Security.Authentication.CloudFoundryBase | < 3.4.0 | - |
|
| SteeltoeOSS | Steeltoe.Security.Authentication.JwtBearer | < 4.2.0 | - |
|
| SteeltoeOSS | Steeltoe.Security.Authentication.OpenIdConnect | < 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50194 | 8.2 HIGH | Steeltoe vulnerable to management-port isolation bypass via spoofed Host header |
| CVE-2026-50196 | 7.5 HIGH | Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch |
| CVE-2026-50200 | 7.5 HIGH | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords |
| CVE-2026-50201 | 6.5 MEDIUM | Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission |
| CVE-2026-50267 | 4.7 MEDIUM | Steeltoe: TLS private keys written to /tmp with default permissions, never deleted |
| CVE-2026-50268 | 1.9 LOW | Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding |
No comments yet