CVE-2020-5412

Description

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
92.108

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-5412 are fixed in Spring-cloud-netflix 2.2.4Windows
Vulnerabilities CVE-2020-5412 are fixed in Spring-cloud-netflix 2.1.6Windows
Vulnerabilities CVE-2020-5412 are fixed in Spring-cloud-netflix for Linux 2.2.4Linux
Vulnerabilities CVE-2020-5412 are fixed in Spring-cloud-netflix for Linux 2.1.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234