← Vulnerability feed

Vulnerability record · CVE-2019-3799 · published 6 May 2019

CVE-2019-3799: Spring Cloud Config Server path traversal exposes arbitrary config files

Vmware · Spring Cloud Config

Spring Cloud Config Server in versions 2.1.x before 2.1.2, 2.0.x before 2.0.4, and 1.4.x before 1.4.6 serves arbitrary configuration files via a crafted URL, enabling directory traversal. Because config servers often hold credentials and connection strings for many services, exposure of these files can be significant.

6.5 CVSS 3.1 Medium EPSS 85% · top 0.3% CWE-22 · Path traversal
6.5CVSS 3.1 base score, v2 4.3
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityHigh confidentiality impact from a remotely reachable path traversal, with very high EPSS despite no KEV listing.

What it is

Spring Cloud Config Server in versions 2.1.x before 2.1.2, 2.0.x before 2.0.4, and 1.4.x before 1.4.6 serves arbitrary configuration files via a crafted URL, enabling directory traversal. Because config servers often hold credentials and connection strings for many services, exposure of these files can be significant.

Impact

An attacker can read files outside the intended configuration directory, potentially obtaining secrets, credentials, and environment-specific configuration data. The CVSS vector shows high confidentiality impact with no integrity or availability impact.

Attack surface

Reachable over the network through the spring-cloud-config-server HTTP endpoint using a specially crafted URL. The CVSS vector indicates no privileges are required but user interaction is required (UI:R), which is unusual for a server-side traversal and should be validated against the actual deployment.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.853, 99.7th percentile), suggesting elevated likelihood of attempted exploitation, though the references only carry vendor advisory and patch tags.

What to do

  • Upgrade Spring Cloud Config Server to 2.1.2, 2.0.4, or 1.4.6 (or later) as applicable to the deployed branch.
  • Apply the Oracle CPU April 2022 patch for affected Oracle products bundling Spring Cloud Config.
  • Restrict network access to the config server endpoint to trusted clients and management networks.
  • Run the config server with least privilege and avoid storing sensitive secrets in traversable configuration paths.

Detection

  • Monitor config server access logs for URL-encoded traversal sequences such as %2e%2e, ..%2f, or repeated ../ in request paths.
  • Alert on requests to the config server from unexpected source IPs or user agents.
  • Review file access and read events for configuration files outside the expected config directory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed7.5CVE-2020-5410Spring Cloud Config Server path traversal exposes arbitrary filesSpring Cloud Config Server versions 2.2.x before 2.2.3, 2.1.x before 2.1.9, and older unsupported releases serve arbitrary configuration files via th…KEVEPSS 96%analysed9.8CVE-2026-47837Vmware spring cloud config missing authentication for critical function vulnerabilityMissing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /mon…EPSS 0.55%9.8CVE-2021-3773Linux kernel information exposure vulnerabilityA flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network …EPSS 5.3%9.8CVE-2021-42392H2 database JNDI lookup flaw allows unauthenticated remote code executionThe org.h2.util.JdbcUtils.getConnection method in the H2 database accepts a driver class name and database URL from the caller. An attacker can suppl…EPSS 83%analysed9.8CVE-2021-23440Set-value project set-value type confusion vulnerabilityThis affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2019-3799), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.