Reflected File Download (RFD) Attack via vulnerable version of Spring Web

XMLWordPrintable

    • Type: Public Security Vulnerability
    • Resolution: Fixed
    • Priority: Low
    • 6.13.20, 7.4.8, 7.10.0, 7.11.3
    • Affects Version/s: 7.0.0
    • Component/s: None
    • None
    • 2
    • Medium
    • CVE-2020-5421

      Affected versions of Atlassian Confluence Server and Data Center used versions of Spring Web that were vulnerable to CVE-2020-5421.

      The affected versions are before version 6.13.20, from version 6.14.0 before 7.4.8, from version 7.5.0 before 7.10.0, and from version 7.11.0 before 7.11.3.

       

      Affected versions:

      • version < 6.13.20
      • 6.14.0 ≤ version < 7.4.8
      • 7.5.0 ≤ version < 7.10.0
      • 7.11.0 ≤ version < 7.11.3

      Fixed versions:

      • 6.13.20
      • 7.4.8
      • 7.10.0
      • 7.11.3  

            Assignee:
            Unassigned
            Reporter:
            Security Metrics Bot
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: