|
|||
Rule General Information |
---|
Release Date: | 2020-06-15 | |
Rule Name: | VMware Spring Cloud Directory Traversal Vulnerability (CVE-2020-5410) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. | |
Impact: | An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information. | |
Affected OS: | Windows, Linux | |
Reference: | https://tanzu.vmware.com/security/cve-2020-5410 |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: https://tanzu.vmware.com/security/cve-2020-5410 |