Spring Cloud Config Server May Not Use Vault Token Sent By Clients
Published Apr 10, 2025
5.3
MEDIUMCVSS 3.1
EPSS 0.31%
Description
Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to Vault. Your application may be affected by this if the following are true: * You have Spring Vault on the classpath of your Spring Cloud Config Server and * You are using the X-CONFIG-TOKEN header to send a Vault token to the Spring Cloud Config Server for the Config Server to use when making requests to Vault and * You are using the default Spring Vault SessionManager implementation LifecycleAwareSessionManager or a SessionManager implementation that persists the Vault token such as SimpleSessionManager.
In this case the SessionManager persists the first token it retrieves and will continue to use that token even if client requests to the Spring Cloud Config Server include a X-CONFIG-TOKEN header with a different value. Affected Spring Products and Versions Spring Cloud Config: * 2.2.1.RELEASE - 4.2.1
Mitigation Users of affected versions should upgrade to the corresponding fixed version.
Affected version(s)Fix versionAvailability4.2.x4.2.2OSS4.1.x4.1.6OSS4.0.x4.0.10Commercial3.1.x3.1.10Commercial3.0.x4.1.6OSS2.2.x4.1.6OSS NOTE: Spring Cloud Config 3.0.x and 2.2.x are no longer under open source or commercial support. Users of these versions are encouraged to upgrade to a supported version.
No other mitigation steps are necessary.
Affected products
-
- Version 2.2.xStatusaffectedConstraints<4.1.6
- Version 3.0.xStatusaffectedConstraints<4.1.6
- Version 3.1.xStatusaffectedConstraints<3.1.10
- Version 4.0.xStatusaffectedConstraints<4.0.10
- Version 4.1.xStatusaffectedConstraints<4.1.6
- Version 4.2.xStatusaffectedConstraints<4.2.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Cloud Config | unaffected |
|
No data.
No data.
A-MQ Clients 2
spring-cloud-config-server
Fix deferred
Red Hat Enterprise Linux 8
log4j:2/log4j
Fix deferred
Red Hat Enterprise Linux 9
log4j
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
spring-cloud-config-server
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
spring-cloud-config-server
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-cloud-config-server
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| A-MQ Clients 2 | spring-cloud-config-server | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | log4j | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-cloud-config-server | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-cloud-config-server | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-cloud-config-server | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
If you cannot upgrade, then you can either:
* Remove Spring Vault from the classpath if it is not needed or * Implement your own SessionManager that does not persist the Vault token and provide a bean using that implementation in a @Configuration class. For example:
public class StatelessSessionManager implements SessionManager {
private final ClientAuthentication clientAuthentication;
private final ReentrantLock lock = new ReentrantLock();
public StatelessSessionManager(ClientAuthentication clientAuthentication) { Assert.notNull(clientAuthentication, "ClientAuthentication must not be null"); this.clientAuthentication = clientAuthentication; }
public VaultToken getSessionToken() { this.lock.lock(); try { return this.clientAuthentication.login(); } finally { this.lock.unlock(); } }
}
@Configuration public class MySessionManagerConfiguration extends SpringVaultClientConfiguration {
private final VaultEnvironmentProperties vaultProperties;
public MySessionManagerConfiguration(VaultEnvironmentProperties vaultProperties, ConfigTokenProvider configTokenProvider, List<springvaultclientauthenticationprovider> authProviders) { super(vaultProperties, configTokenProvider, authProviders); this.vaultProperties = vaultProperties; }
@Bean @Primary public SessionManager sessionManager() { if (vaultProperties.getAuthentication() == null && !StringUtils.hasText(vaultProperties.getToken())) { return new StatelessSessionManager(clientAuthentication()); } return super.sessionManager(); } } </springvaultclientauthenticationprovider>
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.31% (0.00311) | 21.83th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.25% (0.00254) | 16.54th | v5 (v2026.06.15) |
| Apr 11, 2025 | 0.03% (0.00028) | 4.83th | v4 (v2025.03.14) |
References (5)
Change history (0)
No recorded changes yet.