CRITICALMaven

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CVE-2020-5398Published 6 years agoUpdated 5 days agoSource: OSV

Affected packages

  • org.springframework:spring-webflux5.2.0.RELEASE → 5.2.3.RELEASE
  • org.springframework:spring-webmvc5.2.0.RELEASE → 5.2.3.RELEASE

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Sources

Structured record: https://osv.dev/vulnerability/GHSA-8wx2-9q48-vm9r

Recommended response stack

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

Get incidents like this as alerts for your stack.

Join the beta
RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application | HackTribune