Vmware Spring Framework是美国威睿(Vmware)公司的一套开源的Java、JavaEE应用程序框架。该框架可帮助开发人员构建高质量的应用。 Pivotal Software Spring Framework 5.2.3之前的5.2.x版本、5.1.13之前的5.1.x版本和5.0.16之前的5.0.x版本中存在跨站脚本漏洞。远程攻击者可通过实施反射型文件下载(RFD)攻击利用该漏洞获取敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Framework | 5.0< v5.0.16.RELEASE |
affected |
5.1< v5.1.13.RELEASE |
affected | ||
5.2< v5.2.3.RELEASE |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring Framework | 5.0 ~ v5.0.16.RELEASE | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2020-5398 - RFD(Reflected File Download) Attack for Spring MVC | https://github.com/motikan2010/CVE-2020-5398 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet