8.1
CVE-2026-47836
- EPSS 0.08%
- Veröffentlicht 26.08.2026 17:05:21
- Zuletzt bearbeitet 04.09.2026 19:44:58
- Erkennungen
Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Cloud Config Version < 3.1.15
VMware ≫ Spring Cloud Config Version >= 4.0.0 < 4.2.9
VMware ≫ Spring Cloud Config Version >= 4.3.0 < 4.3.5
VMware ≫ Spring Cloud Config Version >= 5.0.0 < 5.0.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.002 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| VMware | 7.2 | 0.8 | 5.8 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://spring.io/security/cve-2026-47836