Executive brief
Spring Cloud Config contains a directory traversal vulnerability in the spring-cloud-config-server module. An unauthenticated attacker can send specially crafted URLs to access and serve arbitrary configuration files from the server's file system.
Affected products
- VMware Tanzu Spring Cloud Config 2.1.x prior to 2.1.9, 2.2.x prior to 2.2.3
Timeline
- 2020-06-02: disclosed: NVD Published Date
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog