Sploitus

CVE-2020-5412

No indexed exploits for CVE-2020-5412 yet

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

Affected products
Spring Cloud Netflix
Vmware Spring Cloud Netflix
< 2.1.6, 2.2.4
CVSS 3.1
6.5 MEDIUM
EPSS
10.2% (95th percentile)
Weakness
CWE-441, CWE-610
NVD status
Modified
Published
2020-08-07
CVE-2020-5412 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-5412 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-5412 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.