References https://nvd.nist.gov/vuln/detail/CVE-2019-3799 https://spring.io/security/cve-2019-3799 https://github.com/mpgn/CVE-2019-3799 https://spring.io/blog/2019/04/17/cve-2019-3799-spring-cloud-config-2-1-2-2-0-4-1-4-6-released https://www.exploit-db.com/exploits/46772 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-3799.yaml https://www.miggo.io/vulnerability-database/cve/CVE-2019-3799 http://chybeta.github.io/2019/04/18/%E3%80%90CVE-2019-3799%E3%80%91-Directory-Traversal-with-spring-cloud-config-server/ https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKCLOUD-174327
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传金蝶eascloud管理控制端任意文件上传PoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDORPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct关于U9 cloud存在接口XML注入漏洞的安全通告关于U9 cloud存在接口SQL注入漏洞的安全通告关于U9 cloud存在接口无授权访问漏洞的安全通告关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告关于NC Cloud及YonBIP高级版系统的公共入口接口漏洞安全通告北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告PoCCVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request Forgery