Skip to content
COOEY

EXPOSURES › CVE-2020-5410

CVE-2020-5410

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-5410 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

A path traversal flaw in VMware Tanzu Spring Cloud Config allowed attackers to serve arbitrary files, leading to potential data exposure and compliance violations.

The vulnerability in VMware Tanzu Spring Cloud Config Server permitted directory traversal, enabling attackers to access arbitrary files on the system. This exposes sensitive configuration data and violates compliance requirements for data protection. DIB organizations should ensure all VMware Tanzu components are patched and monitored for exploitation attempts.

Shame score — A known path traversal vulnerability in a widely used enterprise product that was actively exploited in the wild, indicating a failure to patch or mitigate a known risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized