← All CVEs

CVE-2019-3799

medium · 6.5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

6.5
CVSS
85.3%
EPSS (exploit prob.)
100th
EPSS percentile
2019-05-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
vmwarespring_cloud_config>= 1.4.0, < 1.4.6
vmwarespring_cloud_config>= 2.0.0, < 2.0.4
vmwarespring_cloud_config>= 2.1.0, < 2.1.2
oraclecommunications_cloud_native_core_policy1.15.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-3799