[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Reflected file download vulnerability in SpringSource Spring Framework - CVE-2020-5398

ID: oval:org.secpod.oval:def:89918Date: (C)2023-05-24   (M)2023-11-13
Class: VULNERABILITYFamily: unix




The host is installed with SpringSource Spring Framework 5.0.x before 5.0.16, 5.1.x before 5.1.13, or 5.2.x before 5.2.3 and is prone to a reflected file download vulnerability. A flaw is present in the application, which fails to handle when it sets a "Content-Disposition" header in the response. Successful exploitation allows attackers to allow download of code without integrity check.

Platform:
Linux
Product:
SpringSource Spring Framework
Reference:
CVE-2020-5398
CVE    1
CVE-2020-5398

© SecPod Technologies