Reflected File Download The advisory has been revoked - it doesn't affect any version of package org.springframework:spring-websocket  (opens in a new tab)


Threat Intelligence

EPSS
0.14% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORK-30172
  • published25 Dec 2016
  • disclosed15 Oct 2015
  • creditAlvaro Muñoz

Introduced: 15 Oct 2015

CVE-2015-5211  (opens in a new tab)
CWE-494  (opens in a new tab)

Overview

org.springframework:spring-websocket framework that provides a comprehensive programming and configuration model for modern Java-based enterprise applications - on any kind of deployment platform.

Affected versions of this package are vulnerable to Reflected File Download via a crafted URL with a batch script extension, resulting in the response being downloaded rather than rendered.