Spring.Framework.Header.Reflected.File.Download
Description
This indicates an attack attempt to exploit a Reflected File Download Vulnerability in Spring Framework.
The vulnerability is due to insufficient sanitizing of user-supplied input, which is returned in a file for the user. An attacker can exploit this issue to download a malicious file to the target user's system.
Affected Products
Spring Framework versions 5.2.x before 5.2.3, 5.1.x before 5.1.13, 5.0.x before 5.0.16
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://spring.io/blog/2020/01/16/spring-framework-5-2-3-5-1-13-5-0-16-and-4-3-26-releases
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2021-03-23 | 18.043 | Default_action:pass:drop |