ZeroHour

CVE-2020-5398

CVSS 3.1
7.5 high
EPSS
88%p100
Published
()
Modified
Description

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

Vendors
vmwareoraclenetapp
Products
spring framework, application testing suite, communications billing and revenue management elastic charging engine, communications cloud native core policy, communications diameter signaling router, communications element manager, communications policy management, communications session report manager, communications session route manager, enterprise manager base platform, financial services regulatory reporting with agilereporter, flexcube private banking
Weakness
CWE-79, CWE-494
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.