CVE-2020-5398
גבוהה 7.5
תיאור (מקור, אנגלית)
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - CWE
- CWE-79, CWE-494
מוצרים מושפעים
vmware: spring framework; oracle: application testing suite; oracle: communications billing and revenue management elastic charging engine; oracle: communications cloud native core policy; oracle: communications diameter signaling router; oracle: communications element manager; oracle: communications policy management; oracle: communications session report manager; oracle: communications session route manager; oracle: enterprise manager base platform; oracle: financial services regulatory reporting with agilereporter; oracle: flexcube private banking; oracle: healthcare master person index; oracle: insurance calculation engine; oracle: insurance policy administration j2ee
קישורים
- https://pivotal.io/security/cve-2020-5398 Vendor Advisory
- https://pivotal.io/security/cve-2020-5398 Vendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b…
- https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbda…