Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2019-04-17T00:00:00

Updated: 2022-04-19T23:20:44

Reserved: 2019-01-03T00:00:00


Link: CVE-2019-3799

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-05-06T16:29:01.567

Modified: 2022-06-13T18:45:36.597


Link: CVE-2019-3799

JSON object: View

cve-icon Redhat Information

No data.

CWE