← Back to browse · API

CVE-2020-5410

Severity
HIGH
CVSS
7.5
EPSS
0.95586
Risk score
58.46
CISA KEV
Yes
PoC
No
Published
2020-06-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-0451, GHSA-32XF-JWMV-9HF3
Products
Spring:Spring Cloud Config 2.1 <2.1.9, Spring:Spring Cloud Config 2.2 <2.2.3, VMware Tanzu:Spring Cloud Configuration (Config) Server
Sources
cisa.gov CVE-2020-5410
euvd EUVD-2020-0451

Description

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.

References