8.6
CVE-2026-22739
- EPSS 1.22%
- Veröffentlicht 24.03.2026 00:16:52
- Zuletzt bearbeitet 04.09.2026 20:04:45
- Erkennungen
Spring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable SSRF Attacks
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Cloud Config Version < 3.1.13
VMware ≫ Spring Cloud Config Version >= 4.1.0 < 4.1.9
VMware ≫ Spring Cloud Config Version >= 4.2.0 < 4.2.6
VMware ≫ Spring Cloud Config Version >= 4.3.0 < 4.3.2
VMware ≫ Spring Cloud Config Version >= 5.0.0 < 5.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.22% | 0.647 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 8.6 | 3.9 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://spring.io/security/cve-2026-22739