{"id":"CVE-2020-5410","details":"Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.","aliases":["GHSA-32xf-jwmv-9hf3"],"modified":"2026-08-18T14:31:44.215066Z","published":"2020-06-02T17:15:11.690Z","references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5410"},{"type":"ADVISORY","url":"https://tanzu.vmware.com/security/cve-2020-5410"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spring-cloud/spring-cloud-config","events":[{"introduced":"e62e06c39a7c20af1202a6600e91fc6b50d6a181"},{"fixed":"3450616ea538545d0215bc3080e563b29331d6a4"},{"introduced":"b5bd468c3339a28186b6bd0ee9dd36d2241e674a"},{"fixed":"39264d6ba04609838d912e503662de16937ec4bf"}],"database_specific":{"cpe":"cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.1.0"},{"fixed":"2.1.9"},{"introduced":"2.2.0"},{"fixed":"2.2.3"}],"source":"CPE_RANGE"}}],"versions":["v2.1.8.RELEASE","v2.1.7.RELEASE","v2.2.2.RELEASE","v2.1.6.RELEASE","v2.2.1.RELEASE","v2.2.0.RELEASE","v2.1.5.RELEASE","v2.1.4.RELEASE","v2.1.3.RELEASE","v2.1.2.RELEASE","v2.1.1.RELEASE","v2.1.0.RELEASE"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-5410.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}