Overview
About vulnerability
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.
Details
- Affected product:
- Apache Log4j , Spring
- Affected packages:
- log4j-api @ 2.13.3 (+268 more)