Impact
Spring Cloud Function allows developers to compose functions by name. A logic flaw in the composition lookup can enable an attacker to introduce a malicious lookup that poisons the base function, resulting in altered behavior or unexpected executions. The vulnerability does not provide direct remote code execution, but it can disrupt intended functionality and potentially expose downstream processes to incorrect data or logic. The weakness correlates with poor validation of composition references.
Affected Systems
Spring: Spring Cloud Function versions 3.2.16 and earlier, 4.2.x through 4.2.7, 4.3.x through 4.3.4, and 5.0.x through 5.0.3 are affected.
Risk and Exploitability
The CVSS base score of 3.1 indicates low impact with limited attack scope. No EPSS data is currently available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves manipulating function composition requests from a client, as the composition lookup operates over user‑supplied identifiers. Because no direct exploit data exists, the risk is moderate and primarily tied to service integrity rather than confidentiality or availability.
OpenCVE Enrichment