VDB
Sign up
HIGH7.5

GHSA-32xf-jwmv-9hf3

Directory traversal attack in Spring Cloud Config

Quick fix

GHSA-32xf-jwmv-9hf3 — org.springframework.cloud:spring-cloud-config-server: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.1.9</version> for org.springframework.cloud:spring-cloud-config-server

Details

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework.cloud:spring-cloud-config-server
Introduced in: 2.1.0Fixed in: 2.1.9
Fix# pom.xml: bump <version>2.1.9</version> for org.springframework.cloud:spring-cloud-config-server
Maven/org.springframework.cloud:spring-cloud-config-server
Introduced in: 2.2.0Fixed in: 2.2.3
Fix# pom.xml: bump <version>2.2.3</version> for org.springframework.cloud:spring-cloud-config-server

References