Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Cloud Config allows applications to server arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config:
| Fix version | Availability |
|---|---|
| 5.0.3 | OSS |
| 4.3.3 | OSS |
| 4.2.7 | Enterprise Support Only |
| 4.1.10 | Enterprise Support Only |
| 3.1.14 | Enterprise Support Only |
No further mitigation steps are necessary.
The issue was identified and responsibly reported by Swapnil Paliwal and the security team at AxiomCode using the AxiomEngine, August829, Rashmi Singh from Hive Pro, and Yu Bao - [email protected], from PayPal.com.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy