Steeltoe 是一个开源项目,提供了一系列用于构建云原生应用的库。在 4.3.0 版本之前,Steeltoe 的 端点会通过 处理记录的请求 URI,该机制仅对 URI 中的用户信息进行掩码,但未检查查询字符串。当启用 配置时, 的响应可能会向任何能够访问该显式暴露端点的调用者泄露之前请求中的查询字符串敏感信息,例如 OAuth 令牌、密码重置令牌、签名 URL 的签名、API 密钥等。此外, 的 DEBUG 级别日志记录器也会记录这些 URI,从而为拥有日志访问权限的用户创建了第二条信息泄露途径。该问题已在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SteeltoeOSS | security-advisories | < 4.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81515 | 7.5 HIGH | Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetc |
| CVE-2026-81516 | 7.5 HIGH | Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS |
| CVE-2026-81868 | 6.5 MEDIUM | Steeltoe: Header-forwarded client cert lacks proof of private-key possession |
No comments yet