Vulnerabilities > Vmware > Spring Cloud Config > 1.4.2

DATE CVE VULNERABILITY TITLE RISK
2019-05-06 CVE-2019-3799 Path Traversal vulnerability in multiple products
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module.
network
vmware oracle CWE-22
4.3