#VU111210 Input validation error in Pivotal Spring Framework - CVE-2025-41234
Published: June 17, 2025
Pivotal Spring Framework
Pivotal
Description
The vulnerability allows a remote attacker to perform a reflected file download attack.
The vulnerability exists due to application sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input. A remote attacker can trick the victim into downloading arbitrary files from an attacker controlled location.