Pivotal Spring Cloud Config CVE-2019-3799 Directory Traversal Vulnerability
BID:108289
Info
Pivotal Spring Cloud Config CVE-2019-3799 Directory Traversal Vulnerability
| Bugtraq ID: | 108289 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-3799 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2019 12:00AM |
| Updated: | Apr 16 2019 12:00AM |
| Credit: | Vern from PingAn Galaxy Lab. |
| Vulnerable: |
Pivotal Software Spring Cloud Config 2.1.1 Pivotal Software Spring Cloud Config 2.1 Pivotal Software Spring Cloud Config 2.0.3 Pivotal Software Spring Cloud Config 2.0 Pivotal Software Spring Cloud Config 1.4.5 Pivotal Software Spring Cloud Config 1.4 |
| Not Vulnerable: |
Pivotal Software Spring Cloud Config 2.1.2 Pivotal Software Spring Cloud Config 2.0.4 Pivotal Software Spring Cloud Config 1.4.6 |
Discussion
Pivotal Spring Cloud Config CVE-2019-3799 Directory Traversal Vulnerability
Pivotal Spring Cloud Config is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker could exploit this issue using directory-traversal characters ('../') to access arbitrary files that contain sensitive information. Information harvested may aid in launching further attacks.
Spring Cloud Config 2.1.0 through 2.1.1, 2.0.0 through 2.0.3 and 1.4.0 through 1.4.5 are vulnerable; prior unsupported versions may also be affected.
Pivotal Spring Cloud Config is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker could exploit this issue using directory-traversal characters ('../') to access arbitrary files that contain sensitive information. Information harvested may aid in launching further attacks.
Spring Cloud Config 2.1.0 through 2.1.1, 2.0.0 through 2.0.3 and 1.4.0 through 1.4.5 are vulnerable; prior unsupported versions may also be affected.
Exploit / POC
Pivotal Spring Cloud Config CVE-2019-3799 Directory Traversal Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Pivotal Spring Cloud Config CVE-2019-3799 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Pivotal Spring Cloud Config CVE-2019-3799 Directory Traversal Vulnerability
References:
References:
- ?CVE-2019-3799?:Directory Traversal with spring-cloud-config-server (Chybeta)
- CVE-2019-3799 - Spring-Cloud-Config-Server Directory Traversal < 2.1.2, 2.0.4, 1 (Github)
- CVE-2019-3799: Spring Cloud Config 2.1.2, 2.0.4, 1.4.6 Released (Pivotal)
- Pivotal Homepage (Pivotal)
- Spring Cloud Config Repository (Github)
- CVE-2019-3799: Directory Traversal with spring-cloud-config-server (Pivotal Software)
- Spring Cloud Config Home Page (Pivotal Software)