vendor:
Spring Cloud Config
by:
Vern, Dhiraj Mishra
6.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Spring Cloud Config
Affected Version From: 2.1.x, 2.0.x, 1.4.x
Affected Version To: 2.1.2, 2.0.4, 1.4.6
Patch Exists: YES
Related CWE: CVE-2019-3799
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
Spring Cloud Config Server Directory Traversal
This module exploits an unauthenticated directory traversal vulnerability which exists in Spring Cloud Config versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6. Spring Cloud Config listens by default on port 8888.
Mitigation:
Upgrade to Spring Cloud Config version 2.1.2, 2.0.4, or 1.4.6