Path traversal in Spring Cloud Config - CVE-2020-5410
Published: June 2, 2020 / Updated: March 25, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences through the spring-cloud-config-server module. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Oracle Banking Liquidity Management
How to mitigate CVE-2020-5410
Links to Public Exploits and PoC-codes
- Exploit #5160 - SpringCloud-Config-CVE-2020-5410 (Spring Cloud Config 目录穿越漏洞(CVE-2020-5410) 复现) (February 21, 2021)
- Exploit #4638 - ki-vuln-cve-2020-5410 () (September 21, 2020)
- Exploit #4557 - defvul (Weblogic CVE-2020-14645 coherence 反序列化漏洞验证程序) (September 1, 2020)
- Exploit #3459 - CVE-2020-5410-POC (CVE-2020-5410 Spring Cloud Config directory traversal vulnerability) (July 15, 2020)
- Exploit #3063 - Directory Traversal in Spring Cloud Config Server (July 6, 2020)
- Exploit #3009 - config-demo (CVE-2020-5410) (June 3, 2020)