CVE-2019-3799

    Dashboard / Vulnerabilities / CVE-2019-3799

    CVE-2019-3799

    Published: 6 May 2019Last Modified: 8 Jul 2026

    Summary:

    Details: Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- db63853853de3f3f5ae3d438bb4c9496d55d4c55

    Affected versions

    v2.1.1.RELEASE
    v2.1.0.RELEASE

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High