Vulnerability Description
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Cloud Contract | >= 3.1.0, < 3.1.10 |
Related Weaknesses (CWE)
References
- https://spring.io/security/cve-2024-22236Vendor Advisory
- https://spring.io/security/cve-2024-22236Vendor Advisory
FAQ
What is CVE-2024-22236?
CVE-2024-22236 is a vulnerability with a CVSS score of 3.3 (LOW). In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary d...
How severe is CVE-2024-22236?
CVE-2024-22236 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22236?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Cloud Contract.