CyberRota Analysis
AI-GeneratedThe Spring Cloud Config Server is vulnerable due to improper handling of native environment repositories, which can lead to the exposure of sensitive configuration files outside the designated repository path. This vulnerability could potentially allow unauthorized access to critical configuration data, posing a risk to application security. Organizations using affected versions of Spring Cloud Config should prioritize remediation to mitigate potential data leaks.
Original NVD Description
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)