VDB
Sign up
HIGH7.5

GHSA-8wx2-9q48-vm9r

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

Quick fix

GHSA-8wx2-9q48-vm9r — org.springframework:spring-webmvc: upgrade to the fixed version with the command below.

# pom.xml: bump <version>5.2.3.RELEASE</version> for org.springframework:spring-webmvc

Details

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework:spring-webmvc
Introduced in: 5.2.0.RELEASEFixed in: 5.2.3.RELEASE
Fix# pom.xml: bump <version>5.2.3.RELEASE</version> for org.springframework:spring-webmvc
Maven/org.springframework:spring-webmvc
Introduced in: 5.1.0.RELEASEFixed in: 5.1.13.RELEASE
Fix# pom.xml: bump <version>5.1.13.RELEASE</version> for org.springframework:spring-webmvc
Maven/org.springframework:spring-webmvc
Introduced in: 5.0.0.RELEASEFixed in: 5.0.16.RELEASE
Fix# pom.xml: bump <version>5.0.16.RELEASE</version> for org.springframework:spring-webmvc
Maven/org.springframework:spring-webflux
Introduced in: 5.2.0.RELEASEFixed in: 5.2.3.RELEASE
Fix# pom.xml: bump <version>5.2.3.RELEASE</version> for org.springframework:spring-webflux
Maven/org.springframework:spring-webflux
Introduced in: 5.1.0.RELEASEFixed in: 5.1.13.RELEASE
Fix# pom.xml: bump <version>5.1.13.RELEASE</version> for org.springframework:spring-webflux
Maven/org.springframework:spring-webflux
Introduced in: 5.0.0.RELEASEFixed in: 5.0.16.RELEASE
Fix# pom.xml: bump <version>5.0.16.RELEASE</version> for org.springframework:spring-webflux

References