org.springframework.cloud:spring-cloud-config-server

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.springframework.cloud:spring-cloud-config-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Directory Traversal

[,4.3.2)[5.0.0-M1,5.0.2)
  • M
Improper Authorization

[2.2.0,3.1.10)[4.0.0,4.1.6)[4.2.0,4.2.2)
  • H
Directory Traversal

[2.1.0,2.1.9)[2.2.0,2.2.3)
  • H
Directory Traversal

[2.2.0.RELEASE,2.2.2.RELEASE)[2.1.0.RELEASE,2.1.7.RELEASE)
  • H
Directory Traversal

[,1.4.6.RELEASE)[2.0.0.RELEASE,2.0.4.RELEASE)[2.1.0.RELEASE,2.1.2.RELEASE)

Package versions

101 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
5.0.223 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.0.128 Jan, 2026
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.0.024 Nov, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.0.0-RC112 Nov, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.0.0-M417 Oct, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.0.0-M31 Oct, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.0.0-M210 Sep, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.0.0-M129 Jul, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
4.3.223 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
4.3.116 Dec, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L