References https://nvd.nist.gov/vuln/detail/CVE-2019-3799 https://spring.io/security/cve-2019-3799 https://github.com/mpgn/CVE-2019-3799 https://spring.io/blog/2019/04/17/cve-2019-3799-spring-cloud-config-2-1-2-2-0-4-1-4-6-released https://www.exploit-db.com/exploits/46772 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-3799.yaml https://www.miggo.io/vulnerability-database/cve/CVE-2019-3799 http://chybeta.github.io/2019/04/18/%E3%80%90CVE-2019-3799%E3%80%91-Directory-Traversal-with-spring-cloud-config-server/ https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKCLOUD-174327
Related Vulnerabilities畅捷通T+ERP系统SelectBackupFileOnServer接口处存在目录遍历漏洞PoCCVE-2022-27925: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path TraversalPoCserverless-framework-config-exposure: Serverless Framework - Configuration ExposurePoCterraformrc-credentials-exposure: Terraform CLI Configuration - Credentials ExposurePoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport AccessPoCCVE-2026-87902: WordPress Core - PHP Template Path TraversalPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated Initialize关于U9 cloud存在命令执行漏洞的安全通告关于U9 cloud存在接口反序列化漏洞的安全通告PoCCVE-2026-58467: Cockpit CMS <= 2.14.0 - Path Traversal / Local File InclusionPoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposureCuteHttpFileServer/chfs存在未授权任意文件上传