Vulnerability Intelligence Report
Directory Traversal with spring-cloud-config-server
CVE-2020-5410
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:95.59%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-23 ↗CWE-23: Relative Path Traversal
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Spring by VMware | Spring Cloud Config | 2.1 < 2.1.9 (affected), 2.2 < 2.2.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
95.586%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | pivotal |
| Reserved | 2020-01-03T00:00:00 |
| Published | 2020-06-02T16:50:12 |
| Patch Date | 2020-06-01 |
| Last Updated | 2025-10-21T23:35:43 |
Community Chatter & Buzz