← back
CVE-2019-3799CWE-22

Directory Traversal with spring-cloud-config-server

62Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 85%
from disclosure to weapon0 days
Published on NVDMay 6
1st PoCApr 17
metasploitApr 17
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
1 product
Red Hat Fuse 7
no_fix_planned: Will not fix
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.