CVE-2026-47837
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-306
Ausencia de autenticación para una función crítica
Fecha de publicación:
26/08/2026
Última modificación:
28/08/2026
Descripción
*** Pendiente de traducción *** Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server&#39;s /monitor endpoint are not validated.<br />
<br />
This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.
Impacto
Puntuación base 3.x
6.80
Gravedad 3.x
MEDIA



