CISA Known Exploited Vulnerability

CVE-2020-5410

VMware Tanzu · Spring Cloud Configuration (Config) Server

VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability

Date added
BOD 22-01 due date
CWE CWE-23
Ransomware Unknown

CISA description

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

Required action

Apply updates per vendor instructions.