Exploit for #VU28498 Path traversal in Spring Cloud Config


Published: 2020-06-03 | Updated: 2021-02-21

Vulnerability identifier: #VU28498

Vulnerability risk: Medium

CVSSv3.1: 7.2 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C]

CVE-ID: CVE-2020-5410

CWE-ID: CWE-22

Exploitation vector: Network

Exploits in database: 6

Impact: Information disclosure

Vulnerable software:
Spring Cloud Config
Server applications / Application servers

Vendor: Pivotal