Vmware Spring Cloud Config vulnerabilities
13 known vulnerabilities affecting vmware/spring_cloud_config.
Total CVEs
13
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH6MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2020-5410P1HIGHCVSS 7.5KEVPoC≥ 2.1.0, < 2.1.9≥ 2.2.0, < 2.2.32020-06-02
CVE-2020-5410 [HIGH] CWE-23 CVE-2020-5410: Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsuppo
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
nvd
CVE-2019-3799P2MEDIUMCVSS 6.5PoC≥ 1.4.0, < 1.4.6≥ 2.0.0, < 2.0.4+1 more2019-05-06
CVE-2019-3799 [MEDIUM] CWE-22 CVE-2019-3799: Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a dire
nvd
CVE-2020-5405P2MEDIUMCVSS 6.5PoC≥ 2.1.0, < 2.1.7≥ 2.2.0, < 2.2.22020-03-05
CVE-2020-5405 [MEDIUM] CWE-23 CVE-2020-5405: Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsuppo
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
nvd
CVE-2026-22739P2HIGHCVSS 8.6PoCfixed in 3.1.13≥ 4.1.0, < 4.1.9+3 more2026-03-24
CVE-2026-22739 [HIGH] CWE-22 CVE-2026-22739: Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spr
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X
nvd
CVE-2026-40982P2CRITICALCVSS 9.1≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-40982 [CRITICAL] CWE-22 CVE-2026-40982: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or
nvd
CVE-2026-47837P2CRITICALCVSS 9.8fixed in 3.1.15≥ 4.0.0, < 4.2.9+2 more2026-08-26
CVE-2026-47837 [CRITICAL] CWE-306 CVE-2026-47837: Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webh
Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated.
This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.
nvd
CVE-2026-41002P3HIGHCVSS 8.1≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-41002 [HIGH] CWE-367 CVE-2026-41002: The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: aff
nvd
CVE-2026-40981P3HIGHCVSS 7.5≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-40981 [HIGH] CWE-639 CVE-2026-40981: When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affe
nvd
CVE-2026-47894P3HIGHCVSS 7.5fixed in 3.1.15≥ 4.0.0, < 4.2.9+2 more2026-08-27
CVE-2026-47894 [HIGH] CWE-22 CVE-2026-47894: Spring Cloud Config Server native environment repository allows exposure of configuration files outs
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier
nvd
CVE-2026-47836P3HIGHCVSS 8.1fixed in 3.1.15≥ 4.0.0, < 4.2.9+2 more2026-08-26
CVE-2026-47836 [HIGH] CWE-367 CVE-2026-47836: The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server t
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier
nvd
CVE-2026-59315P4MEDIUMCVSS 5.3fixed in 3.1.15≥ 4.0.0, < 4.2.9+2 more2026-08-27
CVE-2026-59315 [MEDIUM] CWE-400 CVE-2026-59315: The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads.
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier
nvd
CVE-2023-20859P4MEDIUMCVSS 5.5≥ 3.1.0, ≤ 3.1.6≥ 4.0.0, ≤ 4.0.12023-03-23
CVE-2023-20859 [MEDIUM] CWE-532 CVE-2023-20859: In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions,
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
nvd
CVE-2026-41004P4MEDIUMCVSS 4.4≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-41004 [MEDIUM] CWE-532 CVE-2026-41004: When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater
nvd