CVE-2020-5398
—CVSS 3.1
7.5 high
EPSS
88%p100
Published
()
Modified
Description
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
- Vendors
- vmwareoraclenetapp
- Products
- spring framework, application testing suite, communications billing and revenue management elastic charging engine, communications cloud native core policy, communications diameter signaling router, communications element manager, communications policy management, communications session report manager, communications session route manager, enterprise manager base platform, financial services regulatory reporting with agilereporter, flexcube private banking
- Weakness
- CWE-79, CWE-494
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.