Steeltoe.Configuration.Abstractions
Abstractions and code shared by Steeltoe Configuration libraries.
Activity
- Latest release
- 5d ago
- Total releases
- 6
- Cadence
- ~4 months
- Last 12 months
- 3
Details
- License
- Apache-2.0
- First release
- Mar 04, 2025
| Version | Released | |
|---|---|---|
4.3.0
minor
|
4.3.0
minor
Dependencies (1)
|
|
4.2.0
minor
|
4.2.0
minor
Dependencies (1)
|
|
4.1.0
minor
1 CVE
CVE-2026-50267
GHSA-rxrh-4j9h-xgg9
Jul 02, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
SummaryWhen MySQL or PostgreSQL service bindings from ImpactAny process co-located in the container that runs as a different UID can read the TLS client private key from Affected configuration
MitigationsIf an immediate upgrade is not possible, prevent other processes from running in the container under a different UID with access to Affected versions
4.0.0
4.1.0
Fixed in
4.2.0
References Updated Jul 02, 2026 · Source: OSV.dev |
4.1.0
minor
Dependencies (1)
|
|
4.0.0
initial
1 CVE
CVE-2026-50267
GHSA-rxrh-4j9h-xgg9
Jul 02, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
SummaryWhen MySQL or PostgreSQL service bindings from ImpactAny process co-located in the container that runs as a different UID can read the TLS client private key from Affected configuration
MitigationsIf an immediate upgrade is not possible, prevent other processes from running in the container under a different UID with access to Affected versions
4.0.0
4.1.0
Fixed in
4.2.0
References Updated Jul 02, 2026 · Source: OSV.dev |
4.0.0
initial
Dependencies (1)
|
|
4.0.0-rc1
pre
|
4.0.0-rc1
pre
Dependencies (1)
|
|
4.0.0-beta1
pre
|
4.0.0-beta1
pre
Dependencies (1)
|