Impact
The vulnerability resides in Steeltoe.Security.Authorization.Certificate, which accepts the X-Client-Cert header without verifying that the requester holds the corresponding private key. This allows an attacker who knows the public certificate of an application instance to send requests with a forged X-Client-Cert header and bypass SameOrg and SameSpace access controls during the certificate’s validity period. The weakness stems from missing authentication of the private key (CWE-288) and improper use of certificate information (CWE-295).
Affected Systems
Affected products are parts of the Steeltoe open‑source framework used for building cloud‑native applications. The issue exists in all releases prior to 4.3.0 of Steeltoe, particularly the components that implement AddOrgAndSpacePolicies() and UseCertificateAuthorization().
Risk and Exploitability
With a CVSS score of 6.5 and no EPSS data available, the vulnerability is considered medium severity. The vulnerability can be exploited by any attacker who can obtain the public certificate of a target application instance and has network reachability to that instance, provided inbound requests are not filtered to a trusted proxy source. The issue is not listed in the CISA KEV catalog, indicating that publicly known exploits have not yet been reported. However, the attack vector is plausible because common Cloud Foundry routers retain the X-Client-Cert header, and the lack of private‑key proof makes the spoof straightforward.
OpenCVE Enrichment
Github GHSA