Spring Cloud Config, versions 2.1.x before 2.1.2, versions 2.0.x before 2.0.4, and versions 1.4.x before 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vmware spring cloud config |
||
oracle communications cloud native core policy 1.15.0 |