« Back to list

Vmware

Vmware Spring Cloud Config: vulnerabilities and CVEs

Vmware Spring Cloud Config has 13 published vulnerabilities, 9 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.

CVEs13
Last 12 months9
Critical2
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-5410High (7.5)96%⚠ Active exploitationJun 2, 2020
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module.…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-59315Medium (5.3)0.40%—Aug 27, 2026
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud…
CVE-2026-47894High (7.5)0.49%—Aug 27, 2026
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud…
CVE-2026-47837Critical (9.8)0.55%—Aug 26, 2026
Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud…
CVE-2026-47836High (8.1)0.22%—Aug 26, 2026
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 -…
CVE-2026-41004Medium (4.4)0.16%—May 7, 2026
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or…
CVE-2026-41002High (8.1)0.22%—May 7, 2026
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x:…
CVE-2026-40982Critical (9.1)0.82%—May 7, 2026
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can…
CVE-2026-40981High (7.5)0.48%—May 7, 2026
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x:…
CVE-2026-22739High (8.6)1.2%—Mar 24, 2026
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files…
CVE-2023-20859Medium (5.5)0.22%—Mar 23, 2023
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault…
CVE-2020-5410High (7.5)96%⚠ Active exploitationJun 2, 2020
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module.…
CVE-2020-5405Medium (6.5)69%—Mar 5, 2020
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module.…
CVE-2019-3799Medium (6.5)85%—May 6, 2019
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application9
  2. T1005 Data from Local System7
  3. T1078 Valid Accounts1
  4. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Vmware