Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTh3eDItOXE0OC12bTly

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

Permalink: https://github.com/advisories/GHSA-8wx2-9q48-vm9r
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTh3eDItOXE0OC12bTly
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 4 years ago
Updated: about 1 month ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Identifiers: GHSA-8wx2-9q48-vm9r, CVE-2020-5398
References: Repository: https://github.com/spring-projects/spring-framework
Blast Radius: 40.2

Affected Packages

maven:org.springframework:spring-webflux
Dependent packages: 474
Dependent repositories: 3,403
Downloads:
Affected Version Ranges: >= 5.0.0.RELEASE, < 5.0.16.RELEASE, >= 5.1.0.RELEASE, < 5.1.13.RELEASE, >= 5.2.0.RELEASE, < 5.2.3.RELEASE
Fixed in: 5.0.16.RELEASE, 5.1.13.RELEASE, 5.2.3.RELEASE
All affected versions: 5.0.1-0.RELEASE, 5.0.1-1.RELEASE, 5.0.1-2.RELEASE, 5.0.1-3.RELEASE, 5.0.1-4.RELEASE, 5.0.1-5.RELEASE, 5.1.1-0.RELEASE, 5.1.1-1.RELEASE, 5.1.1-2.RELEASE, 5.3.0, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.3.7, 5.3.8, 5.3.9, 5.3.10, 5.3.11, 5.3.12, 5.3.13, 5.3.14, 5.3.15, 5.3.16, 5.3.17, 5.3.18, 5.3.19, 5.3.20, 5.3.21, 5.3.22, 5.3.23, 5.3.24, 5.3.25, 5.3.26, 5.3.27, 5.3.28, 5.3.29, 5.3.30, 5.3.31, 5.3.32, 5.3.33, 5.3.34, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.0.16, 6.0.17, 6.0.18, 6.0.19, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6
All unaffected versions:
maven:org.springframework:spring-webmvc
Dependent packages: 4,621
Dependent repositories: 227,195
Downloads:
Affected Version Ranges: >= 5.0.0.RELEASE, < 5.0.16.RELEASE, >= 5.1.0.RELEASE, < 5.1.13.RELEASE, >= 5.2.0.RELEASE, < 5.2.3.RELEASE
Fixed in: 5.0.16.RELEASE, 5.1.13.RELEASE, 5.2.3.RELEASE
All affected versions: 1.0.1, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 5.0.1-0.RELEASE, 5.0.1-1.RELEASE, 5.0.1-2.RELEASE, 5.0.1-3.RELEASE, 5.0.1-4.RELEASE, 5.0.1-5.RELEASE, 5.1.1-0.RELEASE, 5.1.1-1.RELEASE, 5.1.1-2.RELEASE, 5.3.0, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.3.7, 5.3.8, 5.3.9, 5.3.10, 5.3.11, 5.3.12, 5.3.13, 5.3.14, 5.3.15, 5.3.16, 5.3.17, 5.3.18, 5.3.19, 5.3.20, 5.3.21, 5.3.22, 5.3.23, 5.3.24, 5.3.25, 5.3.26, 5.3.27, 5.3.28, 5.3.29, 5.3.30, 5.3.31, 5.3.32, 5.3.33, 5.3.34, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.0.16, 6.0.17, 6.0.18, 6.0.19, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6
All unaffected versions: