PT-2026-94381 · Steeltoe · Steeltoe
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Steeltoe versions prior to 4.3.0
Description
The
/actuator/httpexchanges endpoint processes recorded request URIs using MaskedUri, which only masks user information and ignores query strings. When the Management:Endpoints:HttpExchanges:IncludeQueryString setting is enabled, the HttpExchangeRequest response may disclose sensitive data from previous traffic, such as OAuth tokens, password-reset tokens, signed-URL signatures, and API keys, to any caller with access to the endpoint. Additionally, the Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger records these URIs, providing another channel for sensitive data disclosure to users with log access.Recommendations
Update to version 4.3.0.
Remove
httpexchanges from the actuator exposure list or restrict it behind authentication.
Set Management:Endpoints:HttpExchanges:IncludeQueryString to false to remove query strings from recorded exchanges.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Steeltoe