ZeroHour

CVE-2020-5412

CVSS 3.1
6.5 medium
EPSS
10%p95
Published
()
Modified
Description

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

Vendors
vmware
Products
spring cloud netflix
Weakness
CWE-441, CWE-610
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.