CVE-2020-5398

Priority
Description
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to
5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to
a reflected file download (RFD) attack when it sets a "Content-Disposition"
header in the response where the filename attribute is derived from user
supplied input.
Notes
Package
Upstream:needs-triage
Ubuntu 18.04 LTS:needs-triage
Ubuntu 20.04 LTS:needs-triage
Ubuntu 21.10:needs-triage
Ubuntu 22.04 LTS:needs-triage
Ubuntu 14.04 ESM:needs-triage
Patches:
More Information

Updated: 2022-04-25 00:50:40 UTC (commit ecc1009cb19540b950de59270950018900f37f15)