Vulnerability record · CVE-2019-3799 · published 6 May 2019
CVE-2019-3799: Spring Cloud Config Server path traversal exposes arbitrary config files
Vmware · Spring Cloud Config
Spring Cloud Config Server in versions 2.1.x before 2.1.2, 2.0.x before 2.0.4, and 1.4.x before 1.4.6 serves arbitrary configuration files via a crafted URL, enabling directory traversal. Because config servers often hold credentials and connection strings for many services, exposure of these files can be significant.
Description
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Automated analysis
high priorityHigh confidentiality impact from a remotely reachable path traversal, with very high EPSS despite no KEV listing.
What it is
Spring Cloud Config Server in versions 2.1.x before 2.1.2, 2.0.x before 2.0.4, and 1.4.x before 1.4.6 serves arbitrary configuration files via a crafted URL, enabling directory traversal. Because config servers often hold credentials and connection strings for many services, exposure of these files can be significant.
Impact
An attacker can read files outside the intended configuration directory, potentially obtaining secrets, credentials, and environment-specific configuration data. The CVSS vector shows high confidentiality impact with no integrity or availability impact.
Attack surface
Reachable over the network through the spring-cloud-config-server HTTP endpoint using a specially crafted URL. The CVSS vector indicates no privileges are required but user interaction is required (UI:R), which is unusual for a server-side traversal and should be validated against the actual deployment.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.853, 99.7th percentile), suggesting elevated likelihood of attempted exploitation, though the references only carry vendor advisory and patch tags.
What to do
- Upgrade Spring Cloud Config Server to 2.1.2, 2.0.4, or 1.4.6 (or later) as applicable to the deployed branch.
- Apply the Oracle CPU April 2022 patch for affected Oracle products bundling Spring Cloud Config.
- Restrict network access to the config server endpoint to trusted clients and management networks.
- Run the config server with least privilege and avoid storing sensitive secrets in traversable configuration paths.
Detection
- Monitor config server access logs for URL-encoded traversal sequences such as %2e%2e, ..%2f, or repeated ../ in request paths.
- Alert on requests to the config server from unexpected source IPs or user agents.
- Review file access and read events for configuration files outside the expected config directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://pivotal.io/security/cve-2019-3799 | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://pivotal.io/security/cve-2019-3799 | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
Track CVE-2019-3799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-3799), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.