Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Very High
CVE-2020-5410
Disclosure Date: June 01, 2020 (last updated February 21, 2025)
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
1
Attacker Value
Unknown
CVE-2023-20859
Disclosure Date: March 23, 2023 (last updated October 08, 2023)
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
0
Attacker Value
Unknown
CVE-2020-5405
Disclosure Date: March 05, 2020 (last updated February 21, 2025)
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
0
Attacker Value
Unknown
Directory Traversal with spring-cloud-config-server
Disclosure Date: May 06, 2019 (last updated November 27, 2024)
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
0