Spring Cloud Config
by Vmware
Take action — actively targeted
Spring Cloud Config is actively targeted by attackers. A significant proportion of its known vulnerabilities are being exploited.
What to do
- Apply all available updates immediately
- Review your exposure — is this internet-facing?
- Monitor vendor advisories for this product
What Attackers Target
Vulnerabilities with high exploit probability
75.0%
Confirmed actively exploited (CISA)
25.0%
Public exploit code available
0.0%
Based on 4 known vulnerabilities. Percentages show the proportion that are actively dangerous — a low percentage means most vulnerabilities in this product are not being exploited.
Most Dangerous Vulnerabilities
| CVE | CVSS | Exploit Probability | Confirmed |
|---|---|---|---|
| CVE-2020-5410 | 7.5 | 94.4% | Yes |
| CVE-2019-3799 | 6.5 | 89.9% | — |
| CVE-2020-5405 | 6.5 | 88.0% | — |
| CVE-2023-20859 | 5.5 | 0.1% | — |
57
/ 100
high-risk
Active Threat
50/50 · Critical
Exploit Availability
7/50 · Minimal
Score uses Wilson score intervals to account for sample size. Products with few CVEs are scored conservatively.