CVE-2026-59315
- EPSS 0.29%
- Veröffentlicht 27.08.2026 18:04:42
- Zuletzt bearbeitet 31.08.2026 23:32:55
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
CVE-2026-47894
- EPSS 0.32%
- Veröffentlicht 27.08.2026 06:17:20
- Zuletzt bearbeitet 01.09.2026 20:37:46
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cl...
CVE-2026-47837
- EPSS 0.28%
- Veröffentlicht 26.08.2026 17:08:51
- Zuletzt bearbeitet 04.09.2026 19:42:43
Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, f...
CVE-2026-47836
- EPSS 0.08%
- Veröffentlicht 26.08.2026 17:05:21
- Zuletzt bearbeitet 04.09.2026 19:44:58
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 ...
CVE-2026-41002
- EPSS 0.22%
- Veröffentlicht 07.05.2026 04:16:25
- Zuletzt bearbeitet 12.05.2026 17:29:53
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1...
CVE-2026-41004
- EPSS 0.17%
- Veröffentlicht 07.05.2026 04:16:25
- Zuletzt bearbeitet 12.05.2026 16:52:55
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). S...
CVE-2026-40981
- EPSS 0.44%
- Veröffentlicht 07.05.2026 04:16:24
- Zuletzt bearbeitet 15.07.2026 02:21:11
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1....
CVE-2026-40982
- EPSS 0.73%
- Veröffentlicht 07.05.2026 04:16:24
- Zuletzt bearbeitet 15.07.2026 02:21:11
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal att...
CVE-2026-22739
- EPSS 1.22%
- Veröffentlicht 24.03.2026 00:16:52
- Zuletzt bearbeitet 04.09.2026 20:04:45
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search di...
CVE-2023-20859
- EPSS 0.22%
- Veröffentlicht 23.03.2023 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:41:42
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.