SteeltoeOSS Steeltoe.Configuration.Encryption是SteeltoeOSS的一个配置加密组件。 SteeltoeOSS Steeltoe.Configuration.Encryption 4.0.0版本至4.1.0版本存在信任管理问题漏洞,该漏洞源于BouncyCastle转换字符串不正确,导致OAEP设置选择了PKCS#1 v1.5算法,可能造成信任管理问题和加密问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SteeltoeOSS | Steeltoe.Configuration.Encryption | >= 4.0.0, < 4.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SteeltoeOSS | Steeltoe.Configuration.Encryption | >= 4.0.0, < 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50194 | 8.2 HIGH | Steeltoe vulnerable to management-port isolation bypass via spoofed Host header |
| CVE-2026-50196 | 7.5 HIGH | Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch |
| CVE-2026-50200 | 7.5 HIGH | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords |
| CVE-2026-50201 | 6.5 MEDIUM | Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission |
| CVE-2026-50202 | 5.9 MEDIUM | Steeltoe's static JWKS cache shared across schemes and never invalidated |
| CVE-2026-50267 | 4.7 MEDIUM | Steeltoe: TLS private keys written to /tmp with default permissions, never deleted |
No comments yet