Lucene search

K
githubGitHub Advisory DatabaseGHSA-8WX2-9Q48-VM9R
HistoryJan 21, 2020 - 8:59 p.m.

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

2020-01-2120:59:09
CWE-79
CWE-494
GitHub Advisory Database
github.com
200

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.625

Percentile

97.8%

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header in the response where the filename attribute is derived from user supplied input.

Affected configurations

Vulners
Node
org.springframeworkspring-webfluxRange5.0.0.RELEASE5.0.16.RELEASE
OR
org.springframeworkspring-webfluxRange5.1.0.RELEASE5.1.13.RELEASE
OR
org.springframeworkspring-webfluxRange5.2.0.RELEASE5.2.3.RELEASE
OR
org.springframeworkspring-webmvcRange5.0.0.RELEASE5.0.16.RELEASE
OR
org.springframeworkspring-webmvcRange5.1.0.RELEASE5.1.13.RELEASE
OR
org.springframeworkspring-webmvcRange5.2.0.RELEASE5.2.3.RELEASE
VendorProductVersionCPE
org.springframeworkspring-webflux*cpe:2.3:a:org.springframework:spring-webflux:*:*:*:*:*:*:*:*
org.springframeworkspring-webmvc*cpe:2.3:a:org.springframework:spring-webmvc:*:*:*:*:*:*:*:*

References

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.625

Percentile

97.8%