Vulnerability reported in spring-security-core-5.1.5.RELEASE.jar 

Issue date: 07-04-2020
Affects versions: 14.0, 13.4

Issue ID

SECURITY-156

 

Affected Product Version(s)

14.0.0, 13.4.2 (and previous patch releases)


Severity 

Medium

Description

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

Source:  MITRE https://nvd.nist.gov/vuln/detail/CVE-2020-5398

Spring Framework has been updated to 5.1.7-RELEASE

Instructions

Every customer is advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.