7.5

CVE-2026-47894

Spring Cloud Config Server Native Environment Repository Exposure

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Cloud Config Version < 3.1.15
VMware ≫ Spring Cloud Config Version >= 4.0.0 < 4.2.9
VMware ≫ Spring Cloud Config Version >= 4.3.0 < 4.3.5
VMware ≫ Spring Cloud Config Version >= 5.0.0 < 5.0.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.239
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
VMware 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.