QID 980299

QID 980299: Java (maven) Security Update for org.springframework:spring-webflux (GHSA-8wx2-9q48-vm9r)

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.6 severity.
  • Solution
    Customers are advised to refer to GHSA-8wx2-9q48-vm9r for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980299

    Software Advisories
    Advisory ID Software Component Link
    GHSA-8wx2-9q48-vm9r org.springframework:spring-webflux URL Logo github.com/advisories/GHSA-8wx2-9q48-vm9r
    GHSA-8wx2-9q48-vm9r org.springframework:spring-webmvc URL Logo github.com/advisories/GHSA-8wx2-9q48-vm9r