Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22312
HistoryJan 17, 2020 - 3:59 a.m.

Reflected File Download

2020-01-1703:59:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.625 Medium

EPSS

Percentile

97.9%

spring-web is vulnerable to reflected file download. The filename attribute that is derived from the user-supplied Content-Disposition header is not validated and sanitized, potentially resulting in the downloaded content of the response to be saved and executed as a file by the user’s browser.

References