nuget package report

Is Steeltoe.Management.EndpointBase safe?

1 known vulnerability, worst severity MODERATE.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so nuget packages are not covered.


      cvss
      0.0
      medium

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 32nd percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-227r-jm2g-7cp4, the advisory selected below

      // 1 advisories

      GHSA-227r-jm2g-7cp4

      MODERATECVE-2026-50201
      // summary

      All Steeltoe actuator endpoints default to EndpointPermissions.Restricted, which is mapped to Cloud Foundry's readbasicdata permission (granted to Space Auditors and similar low-trust roles). Sensitive actuators including heap dump, environment, and thread dump do not raise this to EndpointPermissions.Full, so CF's readsensitivedata permission flag is not enforced for those endpoints. Spring Boot's equivalent Cloud Foundry integration gates these endpoints with readsensitivedata by default.

      // impact

      Any CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAPSERVICES credentials. CF's readsensitivedata permission, which is specifically designed to gate this access, has no effect.

      // affected configuration
      • Application is deployed on Cloud Foundry with CF actuator and security middleware active (added automatically by AddAllActuators() when a CF environment is detected).
      • The attacker holds a CF role that grants readbasicdata: Space Auditor, Space Manager, or Org Auditor.
      // mitigations

      If an immediate upgrade is not possible:

      • Explicitly set RequiredPermissions = EndpointPermissions.Full in the options for HeapDumpEndpointOptions, EnvironmentEndpointOptions, and ThreadDumpEndpointOptions.
      • If heap dump, thread dump, or environment are not needed in production, register only the required actuators individually instead of using AddAllActuators().
      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      Low
      User interaction
      None
      Scope
      Unchanged
      Confidentiality
      High
      Integrity
      None
      Availability
      None

      Checked 2026-09-26 at 01:00 UTC. The most recent advisory here was published 2026-07-02. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.