References https://spring.io/security/cve-2020-5410 https://nvd.nist.gov/vuln/detail/CVE-2020-5410 https://s31k31.github.io/2020/07/03/CVE-2020-5410_Spring_Cloud_Config_Directory_Traversal_New/ https://www.cnblogs.com/Y0uhe/p/15898247.html https://blog.csdn.net/YouthBelief/article/details/121114405 https://avd.aliyun.com/detail?id=AVD-2020-5410 https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/Spring%20Cloud/%EF%BC%88CVE-2020-5410%EF%BC%89Spring%20Cloud%20Config%20%E7%9B%AE%E5%BD%95%E7%A9%BF%E8%B6%8A%E6%BC%8F%E6%B4%9E/ https://www.huaweicloud.com/notice/2018/20200602214144648.html https://github.com/fofapro/vulfocus/blob/master/writeup/Spring_Cloud_Config_Server_%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E_Frivolous-scholar/Spring_Cloud_Config_Server_%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E.md?plain=1 https://zhuanlan.zhihu.com/p/351708906 https://springframework.org.cn/security/cve-2020-5410/ https://github.com/osamahamad/CVE-2020-5410-POC
Related Vulnerabilities金蝶eascloud管理控制端任意文件上传PoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct关于U9 cloud存在接口XML注入漏洞的安全通告关于U9 cloud存在接口SQL注入漏洞的安全通告关于U9 cloud存在接口无授权访问漏洞的安全通告关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告关于NC Cloud及YonBIP高级版系统的公共入口接口漏洞安全通告关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告PoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCCVE-2020-10221: rConfig <= 3.9.4 - Authenticated OS Command InjectionPoCCVE-2026-56270: Flowise <= 3.0.13 - Unauthenticated OAuth Configuration DisclosurePoCccm-detect: Clear-Com Core Configuration Manager Panel - Detect