Bug 2524602 (CVE-2026-47836)
| Summary: | CVE-2026-47836 org.springframework.cloud/spring-cloud-config-server: Spring Cloud Config Server: TOCTOU vulnerability in SVN base directory | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Spring Cloud Config Server. The base directory used by the server to clone SVN repositories is susceptible to a Time-of-Check Time-of-Use (TOCTOU) attack. A local attacker with high privileges could exploit this vulnerability by manipulating the directory between the security check and its subsequent use. This could lead to unauthorized modification of files or disclosure of sensitive information.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2537352 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-26 18:46:58 UTC
|