CVE-2015-5211
Last modified
CVE-2015-5211 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.. EPSS estimates a 2.57% chance of exploitation in the next 30 days.
Description
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Framework | 3.2.0 |
| Vmware | Spring Framework | 3.2.1 |
| Vmware | Spring Framework | 3.2.2 |
| Vmware | Spring Framework | 3.2.3 |
| Vmware | Spring Framework | 3.2.4 |
| Vmware | Spring Framework | 3.2.5 |
| Vmware | Spring Framework | 3.2.6 |
| Vmware | Spring Framework | 3.2.7 |
| Vmware | Spring Framework | 3.2.8 |
| Vmware | Spring Framework | 3.2.9 |
| Vmware | Spring Framework | 3.2.10 |
| Vmware | Spring Framework | 3.2.11 |
| Vmware | Spring Framework | 3.2.12 |
| Vmware | Spring Framework | 3.2.13 |
| Vmware | Spring Framework | 3.2.14 |
| Vmware | Spring Framework | 4.0.0 |
| Vmware | Spring Framework | 4.0.1 |
| Vmware | Spring Framework | 4.0.2 |
| Vmware | Spring Framework | 4.0.3 |
| Vmware | Spring Framework | 4.0.4 |
| Vmware | Spring Framework | 4.0.5 |
| Vmware | Spring Framework | 4.0.6 |
| Vmware | Spring Framework | 4.0.7 |
| Vmware | Spring Framework | 4.0.8 |
| Vmware | Spring Framework | 4.0.9 |
| Vmware | Spring Framework | 4.1.0 |
| Vmware | Spring Framework | 4.1.1 |
| Vmware | Spring Framework | 4.1.2 |
| Vmware | Spring Framework | 4.1.3 |
| Vmware | Spring Framework | 4.1.4 |
| Vmware | Spring Framework | 4.1.5 |
| Vmware | Spring Framework | 4.1.6 |
| Vmware | Spring Framework | 4.1.7 |
| Vmware | Spring Framework | 4.2.0 |
| Vmware | Spring Framework | 4.2.1 |
| Debian | Debian Linux | 8.0 |
References
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlMailing List, Third Party Advisory
- https://pivotal.io/security/cve-2015-5211Vendor Advisory
- https://www.trustwave.com/Resources/SpiderLabs-Blog/Reflected-File-Download---A-New-Web-Attack-Vector/Exploit, Technical Description
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlMailing List, Third Party Advisory
- https://pivotal.io/security/cve-2015-5211Vendor Advisory
- https://www.trustwave.com/Resources/SpiderLabs-Blog/Reflected-File-Download---A-New-Web-Attack-Vector/Exploit, Technical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5211?
How severe is CVE-2015-5211?
How do I fix CVE-2015-5211?
Are you affected by CVE-2015-5211?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
