Reflected File Download (RFD) Attack via vulnerable version of Spring Web

XMLWordPrintable

    • Type: Public Security Vulnerability
    • Resolution: Fixed
    • Priority: Low
    • 6.13.20, 7.4.8, 7.10.0, 7.11.3
    • Affects Version/s: 7.0.0
    • Component/s: None
    • None
    • 2
    • Medium
    • CVE-2020-5421

      Affected versions of Atlassian Confluence Server and Data Center used versions of Spring Web that were vulnerable to CVE-2020-5421.

      The affected versions are before version 6.13.20, from version 6.14.0 before 7.4.8, from version 7.5.0 before 7.10.0, and from version 7.11.0 before 7.11.3.

       

      Affected versions:

      • version < 6.13.20
      • 6.14.0 ≤ version < 7.4.8
      • 7.5.0 ≤ version < 7.10.0
      • 7.11.0 ≤ version < 7.11.3

      Fixed versions:

      • 6.13.20
      • 7.4.8
      • 7.10.0
      • 7.11.3  

              Assignee:
              Unassigned
              Reporter:
              Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: