Executive brief
Steeltoe, a framework for building cloud-native applications, contains a security flaw in how it handles database connections. When connecting to MySQL or PostgreSQL databases using secure TLS certificates, the library writes sensitive private keys to a temporary folder with insecure permissions. This allows other users or malicious processes on the same system to steal these keys and impersonate the application to access the database.
Technical details
The Steeltoe Connectors library (within Steeltoe.Configuration.Abstractions) fails to securely manage temporary credential files when processing MySQL or PostgreSQL service bindings from VCAP_SERVICES. When TLS client credentials are provided, the library uses File.CreateText to write them to Path.GetTempPath(), which defaults to mode 0644 on Linux systems. These files are never deleted by the library. An attacker with local access to the filesystem (such as a co-located process in a container with a different UID) can read the private key and perform mutual TLS authentication to the backing database. The issue is fixed in version 4.2.0 by ensuring user-only access permissions and proper file deletion.
Affected products
- SteeltoeOSS Steeltoe.Configuration.Abstractions >= 4.0.0, <= 4.1.0
Timeline
- 2026-05-20: other: Fix authored in source code
- 2026-05-29: disclosed: Initial advisory publication
- 2026-07-02: advisory: GitHub Advisory Database entry updated