CVE-2020-5398: RFD Attack via “Content-Disposition” Header Sourced from Request Input by Spring MVC or Spring WebFlux Application
Description Affected Spring Products and Versions Mitigation Credit This issue was identified and responsibly reported by Roman Shalymov from EPAM. References https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/reflected-file-download-a-new-web…