Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j623-h46r-v5wr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.

Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.

EPSS

Процентиль: 58%
0.00358
Низкий

Дефекты

CWE-706

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.

EPSS

Процентиль: 58%
0.00358
Низкий

Дефекты

CWE-706