VMware Tanzu Spring Cloud Vulnerability Allows Information Disclosure
Summary
CERT-Bund has issued a security advisory for VMware Tanzu Spring Cloud, detailing a vulnerability that allows remote attackers to disclose information. The advisory affects multiple versions of VMware Tanzu Spring Cloud Config and provides mitigation guidance.
What changed
CERT-Bund has released security advisory WID-SEC-2026-0829 concerning a critical vulnerability (CVSS Base Score 8.6) in VMware Tanzu Spring Cloud. The vulnerability allows remote, anonymous attackers to disclose sensitive information. Affected products include various versions of VMware Tanzu Spring Cloud Config, specifically versions prior to 5.0.2, 4.3.2, 4.2.6, 4.1.9, and 3.1.13. The advisory notes that mitigation measures are available.
Organizations utilizing VMware Tanzu Spring Cloud Config should immediately assess their environment for the affected versions and apply available patches or mitigation strategies to prevent information disclosure. This advisory impacts Linux, UNIX, and Windows operating systems. Given the high CVSS score and remote exploitability, prompt action is recommended to secure affected systems and prevent potential data breaches.
What to do next
- Assess environment for affected VMware Tanzu Spring Cloud Config versions
- Apply available patches or mitigation strategies
- Review system logs for signs of exploitation
Archived snapshot
Mar 24, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
[WID-SEC-2026-0829] VMware Tanzu Spring Cloud: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 8.6 (hoch) CVSS Temporal Score 7.5 (hoch) Remoteangriff ja Datum 23.03.2026 Stand 24.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- Sonstiges
- UNIX
- Windows
Produktbeschreibung
VMware Tanzu Spring Cloud ist eine Plattform zur Bereitstellung und Verwaltung von Spring-Anwendungen in Cloud-Umgebungen unter Verwendung von Microservices-Architekturen.
Produkte
23.03.2026
- VMware Tanzu Spring Cloud Config <5.0.2
VMware Tanzu Spring Cloud Config <4.3.2
VMware Tanzu Spring Cloud Config <4.2.6
VMware Tanzu Spring Cloud Config <4.1.9
VMware Tanzu Spring Cloud Config <3.1.13
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Cloud ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Named provisions
Related changes
Get daily alerts for CERT-Bund Security Advisories
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.