Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2019-3799

больше 7 лет назад

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 4.3
EPSS: Высокий
nvd логотип

CVE-2019-3799

больше 7 лет назад

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 6.5
EPSS: Высокий
github логотип

GHSA-4x49-w62v-76q7

больше 7 лет назад

Path Traversal in Spring Cloud Config

CVSS3: 6.5
EPSS: Высокий
fstec логотип

BDU:2022-02830

больше 7 лет назад

Уязвимость сервера Spring Cloud Config, существующая из-за неверного ограничения имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-3799

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 4.3
85%
Высокий
больше 7 лет назад
nvd логотип
CVE-2019-3799

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 6.5
85%
Высокий
больше 7 лет назад
github логотип
GHSA-4x49-w62v-76q7

Path Traversal in Spring Cloud Config

CVSS3: 6.5
85%
Высокий
больше 7 лет назад
fstec логотип
BDU:2022-02830

Уязвимость сервера Spring Cloud Config, существующая из-за неверного ограничения имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
85%
Высокий
больше 7 лет назад

Уязвимостей на страницу