{"id":"CVE-2020-5412","details":"Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.","aliases":["GHSA-qgcg-p3v2-9h4p"],"modified":"2026-07-08T12:06:01.372690Z","published":"2020-08-07T21:15:10.630Z","references":[{"type":"ADVISORY","url":"https://tanzu.vmware.com/security/cve-2020-5412"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spring-cloud/spring-cloud-netflix","events":[{"introduced":"0"},{"fixed":"2084baf7765f3a97e99d58159e931f84776eed40"},{"introduced":"4164297a89bada128f3363541abbf4151ecb558b"},{"fixed":"a579eb4594713f2f92c90600d74ab7d3930b22b7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.1.6"},{"introduced":"2.2.0"},{"fixed":"2.2.4"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:vmware:spring_cloud_netflix:*:*:*:*:*:*:*:*"}}],"versions":["v2.2.3.RELEASE","v2.2.2.RELEASE","v2.1.5.RELEASE","v2.2.1.RELEASE","v2.2.0.RELEASE","v2.1.4.RELEASE","v2.1.3.RELEASE","v2.1.2.RELEASE","v2.1.1.RELEASE","v2.1.0.RELEASE","v2.1.0.RC3","v2.1.0.M3","v2.1.0.M2","v2.1.0.M1","v2.0.1.RELEASE","v2.0.0.RELEASE","v2.0.0.RC1","v2.0.0.M8","v2.0.0.M7","v2.0.0.M6","v2.0.0.M5","v2.0.0.M4","v2.0.0.M3","v2.0.0.M2","v2.0.0.M1","v1.3.0.RC1","v1.3.0.M1","v1.2.1.RELEASE","v1.2.0.RELEASE","v1.2.0.RC1","v1.2.0.M1","v1.1.0.RELEASE","v1.1.0.RC2","v1.1.0.RC1","v1.1.0.M5","v1.1.0.M4","v1.1.0.M3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5412.json","vanir_signatures_modified":"2026-07-08T12:06:01Z","vanir_signatures":[{"digest":{"line_hashes":["285158692603548749749350948455606305256","5217905107917217778310849651485135156","108580493678423840839642847049751311253","287103919618170015618128359965538168676","301656440108794712526873584674138137885","158311203790284508554830874090751831047","86122229851326873838221440009743627444","300392759837750683799461162892045924898","47791846896821864938606423723708513786","279430314973762484711226481950392689768","21880315820320810906626192467202635602","191371126203530982587792098903668505407","104041375245467534250955829819971445792","158898712404019832611710980888865507369"],"threshold":0.9},"id":"CVE-2020-5412-19b63cd9","signature_type":"Line","signature_version":"v1","source":"https://github.com/spring-cloud/spring-cloud-netflix/commit/2084baf7765f3a97e99d58159e931f84776eed40","target":{"file":"spring-cloud-netflix-turbine-stream/src/test/java/org/springframework/cloud/netflix/turbine/stream/HystrixStreamAggregatorTests.java"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["184163847847077799466818100616538487072","195651531274151872515336816120100637625","160459286270551778996863243857905282742","187752742624531794654732050628154286613"],"threshold":0.9},"id":"CVE-2020-5412-715b5128","signature_type":"Line","signature_version":"v1","source":"https://github.com/spring-cloud/spring-cloud-netflix/commit/2084baf7765f3a97e99d58159e931f84776eed40","target":{"file":"spring-cloud-netflix-zuul/src/main/java/org/springframework/cloud/netflix/zuul/filters/route/RibbonRoutingFilter.java"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}