Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Michael Kimball

Researcher fromOddball
#55648of 56,330
3.3Total CVSS
Vulnerabilities · 1
PT-2024-19288
3.3
2024-01-31
Google · Guava · CVE-2024-22236
**Name of the Vulnerable Software and Affected Versions** Spring Cloud Contract versions 3.1.x prior to 3.1.10 Spring Cloud Contract versions 4.0.x prior to 4.0.5 Spring Cloud Contract versions 4.1.x prior to 4.1.1 **Description** The issue concerns local information disclosure via a temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency. This affects test execution in the specified versions of Spring Cloud Contract. **Recommendations** For versions 3.1.x prior to 3.1.10, update to version 3.1.10 or later. For versions 4.0.x prior to 4.0.5, update to version 4.0.5 or later. For versions 4.1.x prior to 4.1.1, update to version 4.1.1 or later.