VMware

Spring Cloud Config

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 27.08.2026 18:04:42
  • Zuletzt bearbeitet 31.08.2026 23:32:55

The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 06:17:20
  • Zuletzt bearbeitet 01.09.2026 20:37:46

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cl...

  • EPSS 0.28%
  • Veröffentlicht 26.08.2026 17:08:51
  • Zuletzt bearbeitet 04.09.2026 19:42:43

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, f...

  • EPSS 0.08%
  • Veröffentlicht 26.08.2026 17:05:21
  • Zuletzt bearbeitet 04.09.2026 19:44:58

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 ...

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 07.05.2026 04:16:25
  • Zuletzt bearbeitet 12.05.2026 17:29:53

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1...

  • EPSS 0.17%
  • Veröffentlicht 07.05.2026 04:16:25
  • Zuletzt bearbeitet 12.05.2026 16:52:55

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). S...

Medienbericht
  • EPSS 0.44%
  • Veröffentlicht 07.05.2026 04:16:24
  • Zuletzt bearbeitet 15.07.2026 02:21:11

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1....

Medienbericht
  • EPSS 0.73%
  • Veröffentlicht 07.05.2026 04:16:24
  • Zuletzt bearbeitet 15.07.2026 02:21:11

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal att...

  • EPSS 1.22%
  • Veröffentlicht 24.03.2026 00:16:52
  • Zuletzt bearbeitet 04.09.2026 20:04:45

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search di...

  • EPSS 0.22%
  • Veröffentlicht 23.03.2023 21:15:19
  • Zuletzt bearbeitet 21.11.2024 07:41:42

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.