GHSA-4x49-w62v-76q7
GitHub Security Advisory
Path Traversal in Spring Cloud Config
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
Affected Packages
Maven
org.springframework.cloud:spring-cloud-config-server
Affected versions:
0
(fixed in 1.4.6)
Maven
org.springframework.cloud:spring-cloud-config-server
Affected versions:
2.0.0
(fixed in 2.0.4)
Maven
org.springframework.cloud:spring-cloud-config-server
Affected versions:
2.1.0
(fixed in 2.1.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 19, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.