=====================================================================

                                  CERT-Renater

                      Note d'Information No. 2024/VULN072
_____________________________________________________________________

DATE                : 31/01/2024

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Spring Cloud Contract versions
                             prior to 3.1.10, 4.0.5, 4.1.1.

=====================================================================
https://spring.io/security/cve-2024-22236
_____________________________________________________________________

CVE-2024-22236: local information disclosure via temporary directory
created with unsafe permissions
LOW | JANUARY 30, 2024 | CVE-2024-22236


Description

In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions
4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test
execution is vulnerable to local information disclosure via
temporary directory created with unsafe permissions through
the shaded com.google.guava:guava dependency in the
org.springframework.cloud:spring-cloud-contract-shade dependency.


Affected Spring Products and Versions

      Spring Cloud Contract
          4.1.0
          4.0.0 to 4.0.5
          3.1.0 to 3.1.10


Mitigation

Upgrade Spring Cloud Contract to 3.1.10 or 4.0.5 or 4.1.1.

Users of affected versions should apply the following
mitigation. 4.1.x users should upgrade to 4.1.1. 4.0.x users
should upgrade to 4.0.5. 3.1.x users should upgrade to 3.1.10.
No other steps are necessary.  Releases that have fixed this
issue include:

      Spring Cloud Contract
          4.1.1
          4.0.5
          3.1.10

Credit

This issue was identified and responsibly reported by Michael
Kimball from Oddball.


References

      https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415
      https://www.cve.org/cverecord?id=CVE-2020-8908

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
