Description
Potential for logging sensitive data in Spring Cloud Function Azure.
Spring Cloud Function 5.0.0 - 5.0.3
Spring Cloud Function 4.3.0 - 4.3.4
Spring Cloud Function 4.2.0 - 4.2.7
Published: 2026-08-27
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue lets sensitive request or response data be written to application logs when Spring Cloud Function runs on Azure. The default logger configuration captures payloads without filtering, so confidential values can appear verbatim in trace logs, enabling anyone with log access to read data that should remain private.

Affected Systems

Versions 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, and 4.2.0 through 4.2.7 of Spring Cloud Function are affected. Deployments on Microsoft Azure that use these releases should evaluate whether their logging settings capture request or response content that contains sensitive information.

Risk and Exploitability

The CVSS score of 3.1 indicates low to medium severity, and EPSS data is unavailable while the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of active exploitation. The attack vector is inferred to be any user who can invoke the function and read logs at a privileged level, which limits exposure to data that the application logs.

Generated by OpenCVE AI on August 28, 2026 at 08:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a non‑affected release of Spring Cloud Function.
  • Adjust Azure application logging to exclude or mask sensitive fields in request and response bodies so that confidential data is not written to logs.
  • As a temporary measure, disable detailed function logging or implement custom log filters that strip or mask sensitive content until a patch is applied.

Generated by OpenCVE AI on August 28, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Cloud Function
Vendors & Products Spring
Spring spring Cloud Function

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7
Title Potential for logging sensitive data in Spring Cloud Function Azure
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Spring Spring Cloud Function
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-27T17:57:57.960Z

Reserved: 2026-07-04T18:13:46.708Z

Link: CVE-2026-59301

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:56.407

Modified: 2026-08-27T20:17:56.407

Link: CVE-2026-59301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:30:18Z

Weaknesses

No weakness.