HIGH7.5
GHSA-32xf-jwmv-9hf3
Directory traversal attack in Spring Cloud Config
Quick fix
GHSA-32xf-jwmv-9hf3 — org.springframework.cloud:spring-cloud-config-server: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.1.9</version> for org.springframework.cloud:spring-cloud-config-serverDetails
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.springframework.cloud:spring-cloud-config-server
Introduced in:
2.1.0Fixed in: 2.1.9Fix
# pom.xml: bump <version>2.1.9</version> for org.springframework.cloud:spring-cloud-config-serverMaven/org.springframework.cloud:spring-cloud-config-server
Introduced in:
2.2.0Fixed in: 2.2.3Fix
# pom.xml: bump <version>2.2.3</version> for org.springframework.cloud:spring-cloud-config-server