In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Mysql | — | — | Apr 8, 2021 | Jan 17, 2020 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 31535411 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 31537019 for version 12.2.1.4.0. | Jul 14, 2020 | Jan 17, 2020 |
| Progress Moveit Automation | — | Upgrade Progress MOVEit Automation to the latest version | Dec 13, 2024 | Jan 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub