npm package report

Is org.springframework.cloud:spring-cloud-config-server safe?

1 known vulnerability, worst severity MODERATE.

cvss
5.0

how bad it is if exploited, out of 10

epss
68.8%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-g86w-v5vg-9gxf, the advisory selected below

// advisories

GHSA-g86w-v5vg-9gxf

MODERATECVE-2020-5405

Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

Affected
>= 2.2.0, < 2.2.2
Fixed in
2.2.2
Published
2020-06-05
Source
github

GHSANVDMITREreference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:42 UTC. The most recent advisory here was published 2020-06-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.springframework.cloud:spring-cloud-config-server safe? npm package security report | CyberXYZ