spring-boot-actuator-logview_project CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

spring-boot-actuator-logview_project vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to spring-boot-actuator-logview_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-29986 spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view. [email protected] 5.3 0.37% 2023-05-11 2025-01-27
CVE-2021-21234 spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log file directory via admin (spring boot actuator) HTTP endpoints. Both the filename to view and a base folder (relative to the logging folder root) can be specified via request paramet [email protected] 7.7 93.66% 2021-01-05 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence