← Back to browse · API

CVE-2020-5398

Severity
HIGH
CVSS
8.0
EPSS
0.88402
Risk score
62.94
CISA KEV
No
PoC
No
Published
2020-01-16
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-0259, GHSA-8WX2-9Q48-VM9R
Products
VMware:Spring Framework 5.0 <v5.0.16.RELEASE, VMware:Spring Framework 5.1 <v5.1.13.RELEASE, VMware:Spring Framework 5.2 <v5.2.3.RELEASE
Sources
euvd EUVD-2020-0259

Description

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

References