Spring Cloud Config

Vendor:

First CVE: May 6, 2019 · Active for 7 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
12.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Spring Cloud Config over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2019
7 years ago
Most Recent CVE
May 7, 2026
78 days ago

CVE Severity & Scoring

Spring Cloud Config8 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low1 (12.5%)
High1 (12.5%)
None6 (75.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through
Jun 2, 20207.597YESYES
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arb
May 6, 20196.588NOYES
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through
Mar 5, 20206.571NOYES
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request us
May 7, 20269.139NONO
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP
May 7, 20267.533NONO
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTO
May 7, 20268.131NONO
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13
May 7, 20264.421NONO
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log f
Mar 23, 20235.520NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
1 CVE
12.5% of CVEs· 97th percentile
Metasploit
2 CVEs
25.0% of CVEs· 98th percentile
Nuclei
3 CVEs
37.5% of CVEs· 98th percentile
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Spring Cloud Config

Top CWEs

Versions

No cataloged versions.