Логотип exploitDog
bind:CVE-2020-5412
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-5412

Количество 2

Количество 2

nvd логотип

CVE-2020-5412

больше 5 лет назад

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

CVSS3: 6.5
EPSS: Критический
github логотип

GHSA-qgcg-p3v2-9h4p

почти 5 лет назад

Externally Controlled Reference to a Resource in Another Sphere and Confused Deputy in Spring Cloud Netflix

CVSS3: 6.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-5412

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

CVSS3: 6.5
92%
Критический
больше 5 лет назад
github логотип
GHSA-qgcg-p3v2-9h4p

Externally Controlled Reference to a Resource in Another Sphere and Confused Deputy in Spring Cloud Netflix

CVSS3: 6.5
92%
Критический
почти 5 лет назад

Уязвимостей на страницу