Vulnerability record · CVE-2020-5410 · published 2 June 2020
CVE-2020-5410: Spring Cloud Config Server path traversal exposes arbitrary files
Vmware · Spring Cloud Config
Spring Cloud Config Server versions 2.2.x before 2.2.3, 2.1.x before 2.1.9, and older unsupported releases serve arbitrary configuration files via the spring-cloud-config-server module. A crafted URL triggers a directory traversal, letting an unauthenticated remote party read files outside the intended config directory. Because config servers often hold credentials and connection strings, exposure is significant.
Description
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with confirmed exploitation, has a very high EPSS score, and allows unauthenticated remote file disclosure from a server that commonly holds secrets.
What it is
Spring Cloud Config Server versions 2.2.x before 2.2.3, 2.1.x before 2.1.9, and older unsupported releases serve arbitrary configuration files via the spring-cloud-config-server module. A crafted URL triggers a directory traversal, letting an unauthenticated remote party read files outside the intended config directory. Because config servers often hold credentials and connection strings, exposure is significant.
Impact
An attacker gains read access to arbitrary files on the host, including configuration files that may contain secrets, credentials, or environment details. There is no write or code execution impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to the config server endpoint; the CVSS vector shows no privileges or user interaction required. Any exposed spring-cloud-config-server instance is a candidate.
Exploitation
Listed in CISA KEV since 2022-03-25 with a required remediation deadline, indicating known exploitation in the wild. EPSS is very high at 0.956 (99.9th percentile), and no ransomware association is documented.
What to do
- Upgrade Spring Cloud Config Server to 2.2.3 or 2.1.9 (or a later supported release) per the vendor advisory.
- If immediate upgrade is not possible, restrict network access to the config server so only trusted clients can reach it.
- Run the config server with least-privilege filesystem permissions and avoid storing plaintext secrets in reachable paths.
- Rotate any credentials or secrets that may have been exposed through the traversal.
- Monitor vendor advisories for the unsupported older branches, which receive no fixes.
Detection
- Inspect config server access logs for requests containing traversal sequences such as ../ or encoded variants (%2e%2e) in the URL path.
- Alert on requests to config server endpoints from unexpected source IPs or user agents.
- Review filesystem access patterns for the config server process reading files outside its configured search locations.
- Correlate outbound connections or data exfiltration from the config server host after suspicious requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-5410 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://tanzu.vmware.com/security/cve-2020-5410 | Vendor Advisory |
| https://tanzu.vmware.com/security/cve-2020-5410 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5410 | US Government Resource |
Track CVE-2020-5410 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5410), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.