Loading HuntDB...

GHSA-4x49-w62v-76q7

GitHub Security Advisory

Path Traversal in Spring Cloud Config

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

Affected Packages

Maven org.springframework.cloud:spring-cloud-config-server
Affected versions: 0 (fixed in 1.4.6)
Maven org.springframework.cloud:spring-cloud-config-server
Affected versions: 2.0.0 (fixed in 2.0.4)
Maven org.springframework.cloud:spring-cloud-config-server
Affected versions: 2.1.0 (fixed in 2.1.2)

Related CVEs

Key Information

GHSA ID
GHSA-4x49-w62v-76q7
Published
May 23, 2019 8:39 AM
Last Modified
August 3, 2021 9:40 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.springframework.cloud:spring-cloud-config-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 19, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.