EXPOSURES › CVE-2020-5410
CVE-2020-5410
HIGH ⌖ ON CISA KEV · EXPLOITEDA path traversal flaw in VMware Tanzu Spring Cloud Config allowed attackers to serve arbitrary files, leading to potential data exposure and compliance violations.
The vulnerability in VMware Tanzu Spring Cloud Config Server permitted directory traversal, enabling attackers to access arbitrary files on the system. This exposes sensitive configuration data and violates compliance requirements for data protection. DIB organizations should ensure all VMware Tanzu components are patched and monitored for exploitation attempts.
Shame score — A known path traversal vulnerability in a widely used enterprise product that was actively exploited in the wild, indicating a failure to patch or mitigate a known risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |