CVE-2026-47836
Description
A flaw was found in Spring Cloud Config Server. The base directory used by the server to clone SVN repositories is susceptible to a Time-of-Check Time-of-Use (TOCTOU) attack. A local attacker with high privileges could exploit this vulnerability by manipulating the directory between the security check and its subsequent use. This could lead to unauthorized modification of files or disclosure of sensitive information.
Statement
Important: The Spring Cloud Config Server is vulnerable to a Time-of-Check Time-of-Use (TOCTOU) attack within its SVN base directory. Exploitation requires a local attacker with high privileges to manipulate the directory, potentially leading to unauthorized modification of configuration files or disclosure of sensitive data. This risk is present in Red Hat deployments where Spring Cloud Config Server is configured to use SVN repositories.
Mitigation
To mitigate this issue, ensure that the `spring.cloud.config.server.svn.basedir` and the directory where the Spring Cloud Config Server application runs have strict file system permissions, limiting write access to only the necessary service accounts. If SVN repository support is not required, disable it by removing or commenting out the `spring.cloud.config.server.svn.basedir` configuration property from the application's configuration. Restarting the Spring Cloud Config Server application is required for changes to take effect.
Understanding the Weakness (CWE)
Integrity,Other
Technical Impact: Alter Execution Logic; Unexpected State
The attacker can gain access to otherwise unauthorized resources.
Integrity,Other
Technical Impact: Modify Application Data; Modify Files or Directories; Modify Memory; Other
Race conditions such as this kind may be employed to gain read or write access to resources which are not normally readable or writable by the user in question.
Integrity,Other
Technical Impact: Other
The resource in question, or other resources (through the corrupted one), may be changed in undesirable ways by a malicious user.
Non-Repudiation
Technical Impact: Hide Activities
If a file or other resource is written in this method, as opposed to in a valid way, logging of the activity may not occur.
Non-Repudiation,Other
Technical Impact: Other
In some cases it may be possible to delete files a malicious user might not otherwise have access to, such as log files.
Other
Technical Impact: Unexpected State
The product may perform invalid actions when the resource is in an unexpected state.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.