spring-boot-actuator-logview before version 0.2.13 contains a directory traversal vulnerability in libraries that adds a simple logfile viewer as a spring boot actuator endpoint (maven package "eu.hinsch:spring-boot-actuator-logview".
id: CVE-2021-21234
info:
name: Spring Boot Actuator Logview Directory Traversal
author: gy741,p
...