Vulnerability record · CVE-2020-5398 · published 17 January 2020
CVE-2020-5398: Spring Framework reflected file download via Content-Disposition filename
Vmware · Spring Framework
Spring Framework versions 5.2.x before 5.2.3, 5.1.x before 5.1.13, and 5.0.x before 5.0.16 are vulnerable to reflected file download (RFD) when an application builds the Content-Disposition filename attribute from user-supplied input. An attacker who can influence that filename can cause a victim's browser to download an attacker-chosen file, which matters because the file originates from the trusted application's domain.
Description
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 and a very high EPSS percentile indicate significant risk, though exploitation requires user interaction and no KEV listing confirms active abuse.
What it is
Spring Framework versions 5.2.x before 5.2.3, 5.1.x before 5.1.13, and 5.0.x before 5.0.16 are vulnerable to reflected file download (RFD) when an application builds the Content-Disposition filename attribute from user-supplied input. An attacker who can influence that filename can cause a victim's browser to download an attacker-chosen file, which matters because the file originates from the trusted application's domain.
Impact
An attacker can deliver a malicious file that appears to come from the trusted application, potentially leading the victim to execute or open it and enabling code execution or credential theft on the victim's host.
Attack surface
Reached over the network through a crafted request to an endpoint that reflects user input into the Content-Disposition filename; no authentication is required, but the victim must interact with the crafted link or response (UI:R).
Exploitation
Not listed in CISA KEV and no reference tags indicate known exploitation, but EPSS is very high (0.88402, 99.763rd percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Upgrade Spring Framework to 5.2.3, 5.1.13, or 5.0.16 (or later) as applicable.
- Sanitize or encode any user input used in Content-Disposition filename attributes, or avoid deriving filenames from user input.
- Apply vendor patches for the listed Oracle, NetApp, and VMware products that bundle the affected Spring Framework.
- Add response headers such as X-Content-Type-Options: nosniff and a restrictive Content-Disposition policy where feasible.
Detection
- Monitor web and proxy logs for requests whose parameters appear in Content-Disposition filename values in responses.
- Alert on downloads of unexpected file types (for example .html, .js, .exe) served from application endpoints.
- Review application code and WAF rules for endpoints that reflect request parameters into response headers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
33 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-5398 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5398), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.