Spring.Boot.Actuator.Logview.Library.Directory.Traversal
Description
This indicates an attack attempt to exploit a Directory Traversal Vulnerability in spring-boot-actuator-logview library.
The vulnerability is due to insufficient validation of user-supplied paths in the library which adds a logfile viewer as Spring Boot Actuator endpoint. A remote attacker can exploit this vulnerability by sending a crafted request to the target server. Successful exploitation can result in the disclosure of the files outside of the logging base directory.
Affected Products
Spring Boot Actuator Logview prior to 0.2.13
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/lukashinsch/spring-boot-actuator-logview
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |