Showing 1 vulnerability on this page for eu.hinsch:spring-boot-actuator-logview

Signals CISA KEV Ransomware Nuclei
Maven vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Directory Traversal

spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log file directory via admin (spring boot actuator) HTTP endpoints. Both the filename to view and a base folder (relative to the logging folder root) can be specified via request paramet

CWE-22Jan 5, 20211 related artifact
CVSS7.7v3.1EPSS21.2%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX