Lucene search

K
redhatcveRedhat.comRH:CVE-2020-5398
HistoryFeb 06, 2020 - 5:44 p.m.

CVE-2020-5398

2020-02-0617:44:24
redhat.com
access.redhat.com
18

0.625 Medium

EPSS

Percentile

97.9%

A flaw was found in springframework in versions prior to 5.0.16, 5.1.13, and 5.2.3. A reflected file download (RFD) attack is possible when a “Content-Disposition” header is set in response to where the filename attribute is derived from user supplied input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.