Steeltoe.Discovery.ClientAutofac
Steeltoe Service Discovery Client Autofac
Activity
- Latest release
- 4y ago
- Total releases
- 24
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Dec 18, 2017
| Version | Released | |
|---|---|---|
2.5.5
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.5.5
patch
Dependencies (4)
|
|
2.5.4
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.5.4
patch
Dependencies (4)
|
|
2.5.3
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.5.3
patch
Dependencies (4)
|
|
2.5.2
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (4)
|
|
2.5.1
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (4)
|
|
2.5.0
minor
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (4)
|
|
2.4.4
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.4.4
patch
Dependencies (4)
|
|
2.4.3
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.4.3
patch
Dependencies (4)
|
|
2.4.2
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.4.2
patch
Dependencies (4)
|
|
2.4.1
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (4)
|
|
2.4.0
minor
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (4)
|
|
2.4.0-rc1
pre
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.4.0-rc1
pre
Dependencies (4)
|
|
2.3.0
minor
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (4)
|
|
2.3.0-rc2
pre
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.3.0-rc2
pre
Dependencies (4)
|
|
2.3.0-rc1
pre
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.3.0-rc1
pre
Dependencies (4)
|
|
2.2.0
minor
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (4)
|
|
2.2.0-rc2
pre
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.2.0-rc2
pre
Dependencies (4)
|
|
2.2.0-rc1
pre
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.2.0-rc1
pre
Dependencies (4)
|
|
2.1.1
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.1.1
patch
Dependencies (3)
|
|
2.1.0
minor
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (3)
|
|
2.1.0-rc1
pre
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.1.0-rc1
pre
Dependencies (3)
|
|
2.0.1
patch
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.1
patch
Dependencies (3)
|
|
2.0.0
initial
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0
initial
Dependencies (3)
|
|
2.0.0-rc1
pre
1 CVE
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
+ 12 more Show less
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-rc1
pre
Dependencies (3)
|