Impact
This vulnerability allows sensitive data to be inadvertently written to logs during the execution of Spring Cloud Function. The exposed logs could contain personally identifiable information, authentication credentials, or other confidential details, thereby violating privacy and data protection requirements. The flaw is mapped to CWE‑532 (Sensitive Data Storing In Logs).
Affected Systems
Spring Cloud Function versions 5.0.0 – 5.0.3, 4.3.0 – 4.3.4, 4.2.0 – 4.2.7, and 3.2.16 or earlier are affected. Any applications deployed on AWS Lambda that rely on these releases are at risk.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score is less than 1 %, suggesting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is routine function invocation where request payloads are logged; an attacker would need the ability to send inputs that are captured in logs, and the logs must be accessible to them. While the risk is modest, the potential impact on data confidentiality warrants prompt action.
OpenCVE Enrichment