Steeltoe 是一个开源项目,提供了一组帮助开发人员构建云原生应用程序的库。在 4.3.0 版本之前,使用 和 进行配置的 Steeltoe.Security.Authorization.Certificate 部署,会直接信任 请求头中提供的公钥证书,而不会验证请求者是否拥有相应的私钥。 常见的 Cloud Foundry 路由器不会从入站请求中移除该头部。当入站请求未限制来自已知的可信代理源 IP 时,攻击者若能获取目标组织或空间中某个应用程序实例的公钥证书,并且能够访问该应用程序,则可以在该证书有效期内通
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SteeltoeOSS | security-advisories | < 4.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81515 | 7.5 HIGH | Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetc |
| CVE-2026-81516 | 7.5 HIGH | Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS |
| CVE-2026-75523 | 5.9 MEDIUM | Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets |
No comments yet