S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-5412 Scanner

CVE-2020-5412 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Spring Cloud Netflix

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-5412
6.5
CVSS

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Spring Cloud Netflixby Spring by VMware
AFFECTED< 2.2.4SAFE ✓≥ 2.2.4
Updated Aug 21, 2026View on NVD →
Detail

Spring Cloud Netflix is an open-source software suite that allows developers to easily build, deploy, and manage cloud-native applications. It is designed to integrate with the popular Netflix OSS (Open Source Software) components, such as Hystrix, Eureka, and Zuul, to provide developers with a more robust set of tools for creating distributed systems. One of the key benefits of Spring Cloud Netflix is that it simplifies the development process by abstracting away many of the complexities of building cloud-native applications, allowing developers to focus on writing code instead of managing infrastructure.

CVE-2020-5412 is a vulnerability that was recently detected in Spring Cloud Netflix. This vulnerability allows attackers to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server that is reachable from the server hosting the dashboard. This means that a malicious user could potentially send requests to other servers that should not be exposed publicly, leading to potential data leaks, system crashes, or worse.

If the CVE-2020-5412 vulnerability is exploited, it could lead to significant negative consequences for businesses and organizations. Attackers with malicious intent could potentially gain access to sensitive data or disrupt critical systems, leading to loss of revenue, damage to reputation, and potentially even legal consequences. It is important for organizations to take this vulnerability seriously and take steps to protect themselves against potential attacks.

In conclusion, the CVE-2020-5412 vulnerability in Spring Cloud Netflix is a serious issue that should not be taken lightly. However, by taking the appropriate precautions and staying informed about potential threats, organizations can minimize the risk of cyberattacks and protect their digital assets. With the advanced features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets and take the necessary steps to ensure their safety.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability. These include:

  • Updating to the latest version of Spring Cloud Netflix (2.2.4 or 2.1.6, depending on your version).
  • Restricting access to the Hystrix Dashboard proxy.stream endpoint, so that it can only be accessed by authorized users or systems.
  • Implementing network segmentation and access controls to limit the ability of attackers to move laterally within your infrastructure.
  • Monitoring your systems for suspicious activity and reacting quickly to any potential threats.
  • Educating your employees and users on best practices for cybersecurity, such as using strong passwords and avoiding clicking on suspicious links or downloading unknown files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.