Description
Potential for logging sensitive data in Spring Cloud Function AWS.
Spring Cloud Function 5.0.0 - 5.0.3
Spring Cloud Function 4.3.0 - 4.3.4
Spring Cloud Function 4.2.0 - 4.2.7
Spring Cloud Function 3.2.16 and earlier
Published: 2026-08-27
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Spring Cloud Function 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, 4.2.0 through 4.2.7, and all 3.2.16 versions or earlier may log sensitive data. The flaw allows unintended exposure of confidential information in logs, which could be accessed by an attacker with read access to log files or through compromised infrastructure. The anomaly is a lower severity vulnerability with a CVSS score of 3.1, meaning that the impact is generally limited to confidentiality without affecting integrity or availability.

Affected Systems

Affected users include those running Spring Cloud Function from version 5.0.0 to 5.0.3, 4.3.0 to 4.3.4, 4.2.0 to 4.2.7, and 3.2.16 and earlier. The issue exists across the library’s implementations for Amazon Web Services, potentially impacting any applications that rely on the function framework for event handling.

Risk and Exploitability

The risk is considered low because the CVSS score is 3.1 and there is no evidence of active exploitation (EPSS not available and not listed in KEV). Successful exploitation requires access to log data, so the attack vector is likely local or requires privileged access to the hosting environment. While it is not a critical threat, any access to logs could reveal sensitive user or system data.

Generated by OpenCVE AI on August 28, 2026 at 06:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Spring Cloud Function 5.0.4 or newer, or update to the latest minor release from 4.3.x, 4.2.x, or 3.2.x that addresses logging practices
  • Modify application logging configuration to exclude sensitive payloads and implement log sanitization
  • Audit existing logs for sensitive data that might have been captured and purge or redact as necessary

Generated by OpenCVE AI on August 28, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Cloud Function
Vendors & Products Spring
Spring spring Cloud Function

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
Title Potential for logging sensitive data in Spring Cloud Function AWS
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Spring Spring Cloud Function
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-27T17:57:57.010Z

Reserved: 2026-07-04T18:13:46.708Z

Link: CVE-2026-59300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:56.293

Modified: 2026-08-27T20:17:56.293

Link: CVE-2026-59300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor