QID 980959
QID 980959: Java (maven) Security Update for org.springframework:spring-core (GHSA-pgf9-h69p-pcgf)
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pgf9-h69p-pcgf for updates pertaining to this vulnerability.
Vendor References
- GHSA-pgf9-h69p-pcgf -
github.com/advisories/GHSA-pgf9-h69p-pcgf
CVEs related to QID 980959
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pgf9-h69p-pcgf | org.springframework:spring-core |
|