CVE-2015-5211
published 2017-05-25CVE-2015-5211: Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File…
PriorityP344critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
2.57%
83.5th percentile
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
Affected
116 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libspring-java | < libspring-java 4.1.9-1 (bookworm) | libspring-java 4.1.9-1 (bookworm) |
| debian | libspring-java | < libspring-java 4.3.30-1 (bookworm) | libspring-java 4.3.30-1 (bookworm) |
| oracle | commerce_guided_search | — | — |
| oracle | communications_brm | — | — |
| oracle | communications_brm | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_session_report_manager | 8.2.1 – 8.2.2.1 | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | endeca_information_discovery_integrator | — | — |
| oracle | enterprise_data_quality | — | — |
| oracle | enterprise_data_quality | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.1.0 | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | goldengate_application_adapters | — | — |
| oracle | healthcare_master_person_index | — | — |
| oracle | hyperion_infrastructure_technology | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | — | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
ghsa9.6CRITICAL
osv9.6CRITICAL
vendor_debian9.6LOW
vendor_redhat9.6CRITICAL
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Spring Framework
osv·2021-04-30·CVSS 9.6
CVE-2020-5421 [CRITICAL] Improper Input Validation in Spring Framework
Improper Input Validation in Spring Framework
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
GHSA
Improper Input Validation in Spring Framework
ghsa·2021-04-30·CVSS 9.6
CVE-2020-5421 [CRITICAL] CWE-35 Improper Input Validation in Spring Framework
Improper Input Validation in Spring Framework
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
OSV
libspring-java vulnerabilities
osv·2021-03-17·CVSS 8.8
CVE-2015-3192 [HIGH] libspring-java vulnerabilities
libspring-java vulnerabilities
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of ser
OSV
CVE-2020-5421: In Spring Framework versions 5
osv·2020-09-19·CVSS 9.6
CVE-2020-5421 [CRITICAL] CVE-2020-5421: In Spring Framework versions 5
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
GHSA
Files or Directories Accessible to External Parties in org.springframework:spring-core
ghsa·2018-10-17
CVE-2015-5211 [HIGH] CWE-20 Files or Directories Accessible to External Parties in org.springframework:spring-core
Files or Directories Accessible to External Parties in org.springframework:spring-core
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
OSV
Files or Directories Accessible to External Parties in org.springframework:spring-core
osv·2018-10-17
CVE-2015-5211 [HIGH] Files or Directories Accessible to External Parties in org.springframework:spring-core
Files or Directories Accessible to External Parties in org.springframework:spring-core
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
OSV
CVE-2015-5211: Under some situations, the Spring Framework 4
osv·2017-05-25·CVSS 9.6
CVE-2015-5211 [CRITICAL] CVE-2015-5211: Under some situations, the Spring Framework 4
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
Ubuntu
Spring Framework vulnerabilities
vendor_ubuntu·2021-03-17·CVSS 8.8
CVE-2015-5211 [HIGH] Spring Framework vulnerabilities
Title: Spring Framework vulnerabilities
Summary: Several security issues were fixed in Spring Framework.
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this is
Red Hat
springframework: RFD protection bypass via jsessionid
vendor_redhat·2020-09-17·CVSS 9.6
CVE-2020-5421 [CRITICAL] springframework: RFD protection bypass via jsessionid
springframework: RFD protection bypass via jsessionid
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
In Spring Framework, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Statement: This issue does not affect the version of SpringFramework (embedded in rhvm-dependencies) shipped with Red Hat Virtualization, as it does not provide support for spring-web.
In Red Hat Gluster Storage 3, SpringFramework (embedded in rhvm-dependencies) was shipped as a part of Red Hat Glus
Debian
CVE-2020-5421: libspring-java - In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3....
vendor_debian·2020·CVSS 9.6
CVE-2020-5421 [CRITICAL] CVE-2020-5421: libspring-java - In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3....
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Scope: local
bookworm: resolved (fixed in 4.3.30-1)
bullseye: resolved (fixed in 4.3.30-1)
forky: resolved (fixed in 4.3.30-1)
sid: resolved (fixed in 4.3.30-1)
trixie: resolved (fixed in 4.3.30-1)
Debian
CVE-2015-5211: libspring-java - Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2....
vendor_debian·2015·CVSS 9.6
CVE-2015-5211 [CRITICAL] CVE-2015-5211: libspring-java - Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2....
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
Scope: local
bookworm: resolved (fixed in 4.1.9-1)
bullseye: resolved (fixed in 4.1.9-1)
forky: resolved (fixed in 4.1.9-1)
sid: resolved (fixed in 4.1.9-1)
trixie: resolved (fixed in 4.1.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Content-Disposition filename truncation leads to Reflected File Download
bugzilla·2022-08-11·CVSS 9.6
[CRITICAL] Content-Disposition filename truncation leads to Reflected File Download
Content-Disposition filename truncation leads to Reflected File Download
User-Agent:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:103.0) Gecko/20100101 Firefox/103.0
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0
When handling filename directive in the Content-Disposition header, the filename would be truncated if the token contains a NULL character and only the first part is kept: `filename.exe.txt` -> `filename.exe`
This behavior makes Firefox users vulnerable to reflected file download (RFD). For instance, CVE-2022-36359[1] in Django that has been patched[2] is still exploitable on Firefox because the filename truncation provides a trivial way to manipulate and bypass e
Bugzilla
CVE-2020-5421 springframework: RFD protection bypass via jsessionid
bugzilla·2020-09-21·CVSS 9.6
CVE-2020-5421 [CRITICAL] CVE-2020-5421 springframework: RFD protection bypass via jsessionid
CVE-2020-5421 springframework: RFD protection bypass via jsessionid
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Reference:
https://tanzu.vmware.com/security/cve-2020-5421
Discussion:
Created springframework tracking bugs for this issue:
Affects: fedora-all [bug 1881159]
---
Statement:
This issue does not affect the version of SpringFramework (embedded in rhvm-dependencies) shipped with Red Hat Virtualization, as it does not provide support for spring-web.
In Red Hat Gluster Storage 3, SpringFramework (embedded in rhvm-dependencies) was shipped as a part of
Bugzilla
CVE-2015-5211 springframework: Spring Framework: Reflected File Download (RFD) vulnerability [fedora-all]
bugzilla·2015-10-19·CVSS 9.6
CVE-2015-5211 [CRITICAL] CVE-2015-5211 springframework: Spring Framework: Reflected File Download (RFD) vulnerability [fedora-all]
CVE-2015-5211 springframework: Spring Framework: Reflected File Download (RFD) vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2015-5211 Spring Framework: Reflected File Download (RFD) vulnerability
bugzilla·2015-10-19·CVSS 9.6
CVE-2015-5211 [CRITICAL] CVE-2015-5211 Spring Framework: Reflected File Download (RFD) vulnerability
CVE-2015-5211 Spring Framework: Reflected File Download (RFD) vulnerability
Under some situations, the Spring Framework is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
Users of affected Spring Framework versions should upgrade as follows:
- 3.2.x upgrade to 3.2.15+.
- 4.0.x and 4.1.x upgrade to 4.1.8+.
- 4.2.x upgrade to 4.2.2+.
Upstream bug:
https://jira.spring.io/browse/SPR-13548
Upstream patches:
https://github.com/spring-projects/spring-framework/commit/2bd1da
https://github.com/spring-projects/spring-framework/commit/a95c3d
https://github.com/spring-projects/spring-fr
https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttps://pivotal.io/security/cve-2015-5211https://www.trustwave.com/Resources/SpiderLabs-Blog/Reflected-File-Download---A-New-Web-Attack-Vector/https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttps://pivotal.io/security/cve-2015-5211https://www.trustwave.com/Resources/SpiderLabs-Blog/Reflected-File-Download---A-New-Web-Attack-Vector/
2017-05-25
Published