CVE-2020-5410: VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
A flaw was found in spring-cloud-config in versions prior to 2.1.9 and 2.2.3. Applications are allowed to serve arbitrary configuration files through the spring-cloud-config-server module allowing an attacker to send a request using a specially crafted URL to create a directory traversal attack. The highest threat from this vulnerability is to data confidentiality.
Other sources
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/spring-cloud-configto a version that resolves this vulnerability.Fixed in 2.2.3 - Upgrade
Upgrade
redhat/spring-cloud-configto a version that resolves this vulnerability.Fixed in 2.1.9 - Upgrade
Upgrade
spring-cloud-config-server (Spring Cloud Config)to a version that resolves this vulnerability.Fixed in 2.1.9 - Upgrade
Upgrade
spring-cloud-config-server (Spring Cloud Config)to a version that resolves this vulnerability.Fixed in 2.2.3 - Compensating control
Restrict spring-cloud-config-server so it is only accessible on internal networks.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-5410?
CVE-2020-5410 is a directory traversal vulnerability found in VMware Tanzu Spring Cloud Config.
How does CVE-2020-5410 affect VMware Tanzu Spring Cloud Config?
CVE-2020-5410 allows an attacker to create a directory traversal attack by sending a specially crafted URL request to the spring-cloud-config-server module, allowing them to serve arbitrary configuration files.
What is the severity of CVE-2020-5410?
CVE-2020-5410 has a severity value of 7.5 (High).
Which versions of VMware Tanzu Spring Cloud Config are affected by CVE-2020-5410?
Versions prior to 2.1.9 and 2.2.3 of VMware Tanzu Spring Cloud Config are affected by CVE-2020-5410.
How can I fix CVE-2020-5410?
To fix CVE-2020-5410, update your VMware Tanzu Spring Cloud Config to version 2.1.9 or 2.2.3.