Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Cloud Config allows applications to server arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 3.1.x | 3.1.14 | Enterprise Support Only |
| 4.1.x | 4.1.10 | Enterprise Support Only |
| 4.2.x | 4.2.7 | Enterprise Support Only |
| 4.3.x | 4.3.3 | OSS |
| 5.0.x | 5.0.3 | OSS |
The issue was identified and responsibly reported by Swapnil Paliwal and the security team at AxiomCode using the AxiomEngine, August829, and rash18mi.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy