#VU50663 Externally controlled reference to a resource in another sphere in Spring Cloud Netflix - CVE-2020-5412
Published: February 12, 2021
Spring Cloud Netflix
Spring
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the application allows to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A remote user can send a request to other servers that should not be exposed publicly.