Impact
Spring Cloud Function 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, 4.2.0 through 4.2.7, and all 3.2.16 versions or earlier may log sensitive data. The flaw allows unintended exposure of confidential information in logs, which could be accessed by an attacker with read access to log files or through compromised infrastructure. The anomaly is a lower severity vulnerability with a CVSS score of 3.1, meaning that the impact is generally limited to confidentiality without affecting integrity or availability.
Affected Systems
Affected users include those running Spring Cloud Function from version 5.0.0 to 5.0.3, 4.3.0 to 4.3.4, 4.2.0 to 4.2.7, and 3.2.16 and earlier. The issue exists across the library’s implementations for Amazon Web Services, potentially impacting any applications that rely on the function framework for event handling.
Risk and Exploitability
The risk is considered low because the CVSS score is 3.1 and there is no evidence of active exploitation (EPSS not available and not listed in KEV). Successful exploitation requires access to log data, so the attack vector is likely local or requires privileged access to the hosting environment. While it is not a critical threat, any access to logs could reveal sensitive user or system data.
OpenCVE Enrichment