Executive brief
Steeltoe is a framework used to build cloud-native .NET applications. A vulnerability in its management tools allows low-privileged users on Cloud Foundry to access sensitive diagnostic data, such as memory dumps and environment variables. This could lead to the exposure of database passwords, security tokens, and other confidential credentials, potentially allowing an attacker to gain deeper access to the organization's infrastructure.
Technical details
Steeltoe actuator endpoints default to 'EndpointPermissions.Restricted', which maps to Cloud Foundry's 'read_basic_data' permission. This level of access is granted to low-trust roles such as Space Auditors and Org Auditors. Sensitive endpoints—specifically heapdump, env, and thread dump—fail to require 'EndpointPermissions.Full' (mapped to 'read_sensitive_data'). Consequently, an authenticated attacker with basic auditor privileges can retrieve a heap dump containing in-memory secrets like database credentials and bearer tokens. The issue is resolved in Steeltoe.Management.Endpoint 4.2.0 and Steeltoe.Management.EndpointBase 3.4.0.
Affected products
- SteeltoeOSS Steeltoe.Management.Endpoint <= 4.1.0
- SteeltoeOSS Steeltoe.Management.EndpointBase <= 3.3.0
Timeline
- 2026-05-29: disclosed
- 2026-06-17: advisory: NVD publication date
- 2026-07-02: patched: GitHub Advisory updated with patched versions
References
- https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-227r-jm2g-7cp4
- https://github.com/SteeltoeOSS/Steeltoe/commit/b39defa4db5f44f8696c456866b3a5b900d8d96b
- https://github.com/SteeltoeOSS/Steeltoe/commit/da6c604decd992f61aeef763f5814102dcb088c7
- https://api.github.com/repos/SteeltoeOSS/security-advisories/security-advisories/GHSA-227r-jm2g-7cp4