CVE-2020-5398

HIGH

Spring Framework 5.0.0-5.0.15, 5.1.0-5.1.12, 5.2.0-5.2.2 - Reflected File Download via Content-Disposition Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-5398. PoCs published by motikan2010.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2020-5398, demonstrating a Reflected File Download (RFD) attack in Spring MVC. The PoC includes a Spring Boot application that allows user-controlled input to be reflected in the 'Content-Disposition' header, enabling malicious file downloads.

Description

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

Exploits (1)

nomisec WORKING POC 87 stars
by motikan2010 · poc
https://github.com/motikan2010/CVE-2020-5398

This repository contains a functional proof-of-concept for CVE-2020-5398, demonstrating a Reflected File Download (RFD) attack in Spring MVC. The PoC includes a Spring Boot application that allows user-controlled input to be reflected in the 'Content-Disposition' header, enabling malicious file downloads.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Spring Framework versions 5.2.x prior to 5.2.3, 5.1.x prior to 5.1.13, and 5.0.x prior to 5.0.16
No auth needed
Prerequisites: A vulnerable Spring MVC application that reflects user input in the 'Content-Disposition' header
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (44)

Core 44
Core References
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2020-5398
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210917-0006/
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html

Scores

CVSS v3 7.5
EPSS 0.8797
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-494 CWE-79
Status published
Products (50)
netapp/data_availability_services
netapp/snapcenter
oracle/application_testing_suite 13.3.0.1
oracle/communications_billing_and_revenue_management_elastic_charging_engine 11.3
oracle/communications_billing_and_revenue_management_elastic_charging_engine 12.0
oracle/communications_cloud_native_core_policy 1.5.0
oracle/communications_diameter_signaling_router 8.0.0 - 8.2.2
oracle/communications_element_manager 8.1.1
oracle/communications_element_manager 8.2.0
oracle/communications_element_manager 8.2.1
... and 40 more
Published Jan 17, 2020
Tracked Since Feb 18, 2026