Junglewise Threat Intelligence

CVE-2020-5410: Directory traversal attack in Spring Cloud Config

CVE-2020-5410 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-06-05

Executive brief

Spring Cloud Config contains a directory traversal vulnerability in the spring-cloud-config-server module. An unauthenticated attacker can send specially crafted URLs to access and serve arbitrary configuration files from the server's file system.

Affected products

  • VMware Tanzu Spring Cloud Config 2.1.x prior to 2.1.9, 2.2.x prior to 2.2.3

Timeline

  • 2020-06-02: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog