CVE-2020-5398

🟡 Monitoruj

Atak RFD w Spring Framework pozwala na pobranie pliku z złośliwą nazwą.

CVSS
7.5
EPSS
88.8%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)88.8%
Opublikowano (NVD)2020-01-17 00:15:12 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:17:00 UTC
Referencje