← Vulnerability feed

Vulnerability record · CVE-2020-5410 · published 2 June 2020

CVE-2020-5410: Spring Cloud Config Server path traversal exposes arbitrary files

Vmware · Spring Cloud Config

Spring Cloud Config Server versions 2.2.x before 2.2.3, 2.1.x before 2.1.9, and older unsupported releases serve arbitrary configuration files via the spring-cloud-config-server module. A crafted URL triggers a directory traversal, letting an unauthenticated remote party read files outside the intended config directory. Because config servers often hold credentials and connection strings, exposure is significant.

7.5 CVSS 3.1 High CISA KEV since 25 Mar 2022 EPSS 96% · top 0.1% CWE-23 · Relative path traversalCWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with confirmed exploitation, has a very high EPSS score, and allows unauthenticated remote file disclosure from a server that commonly holds secrets.

What it is

Spring Cloud Config Server versions 2.2.x before 2.2.3, 2.1.x before 2.1.9, and older unsupported releases serve arbitrary configuration files via the spring-cloud-config-server module. A crafted URL triggers a directory traversal, letting an unauthenticated remote party read files outside the intended config directory. Because config servers often hold credentials and connection strings, exposure is significant.

Impact

An attacker gains read access to arbitrary files on the host, including configuration files that may contain secrets, credentials, or environment details. There is no write or code execution impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP requests to the config server endpoint; the CVSS vector shows no privileges or user interaction required. Any exposed spring-cloud-config-server instance is a candidate.

Exploitation

Listed in CISA KEV since 2022-03-25 with a required remediation deadline, indicating known exploitation in the wild. EPSS is very high at 0.956 (99.9th percentile), and no ransomware association is documented.

What to do

  • Upgrade Spring Cloud Config Server to 2.2.3 or 2.1.9 (or a later supported release) per the vendor advisory.
  • If immediate upgrade is not possible, restrict network access to the config server so only trusted clients can reach it.
  • Run the config server with least-privilege filesystem permissions and avoid storing plaintext secrets in reachable paths.
  • Rotate any credentials or secrets that may have been exposed through the traversal.
  • Monitor vendor advisories for the unsupported older branches, which receive no fixes.

Detection

  • Inspect config server access logs for requests containing traversal sequences such as ../ or encoded variants (%2e%2e) in the URL path.
  • Alert on requests to config server endpoints from unexpected source IPs or user agents.
  • Review filesystem access patterns for the config server process reading files outside its configured search locations.
  • Correlate outbound connections or data exfiltration from the config server host after suspicious requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-5410 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5410 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-47837Vmware spring cloud config missing authentication for critical function vulnerabilityMissing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /mon…EPSS 0.55%9.1CVE-2026-40982Vmware spring cloud config path traversal vulnerabilitySpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or …EPSS 0.82%8.6CVE-2026-22739Vmware spring cloud config path traversal vulnerabilityVulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native …EPSS 1.2%8.1CVE-2026-47836Vmware spring cloud config toctou race condition vulnerabilityThe base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to tim…EPSS 0.22%8.1CVE-2026-41002Vmware spring cloud config toctou race condition vulnerabilityThe base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to t…EPSS 0.22%7.5CVE-2026-47894Vmware spring cloud config vulnerabilitySpring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Clo…EPSS 0.49%7.5CVE-2026-40981Vmware spring cloud config insecure direct object reference vulnerabilityWhen using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially expos…EPSS 0.48%6.5CVE-2020-5405Spring Cloud Config Server path traversal in config file servingSpring Cloud Config Server versions 2.2.x before 2.2.2, 2.1.x before 2.1.7, and older unsupported releases can be made to serve arbitrary configurati…EPSS 69%analysed

Source: NIST National Vulnerability Database (record CVE-2020-5410), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.