Sentinel 控制台 Spring Framework 反射型文件下载漏洞(CVE-2020-5398)
- Dominant language
- Java
- Stars
- 23.1k
- Forks
- 8.1k
- PR merge metrics
- No merged PRs in 30d
Description
## Issue Description
Type: *bug report* or *feature request*
### Describe what happened (or what feature you want)
https://github.com/alibaba/Sentinel/blob/master/sentinel-dashboard/pom.xml
Sentinel 控制台 Spring Framework 反射型文件下载漏洞(CVE-2020-5398)
当前 pom 引入的 springboot版本2.0.5.RELEASE对应的是spring-web-5.0.9.RELEASE
该版本存在一个已发现漏洞
### Describe what you expected to happen
### How to reproduce it (as minimally and precisely as possible)
1.
2.
3.
### Tell us your environment
### Anything else we need to know?
Contributor guide
Research direction
Start with sentinel-dashboard/pom.xml and inspect the Spring Boot and spring-web versions identified in the report. Check which dependency version addresses CVE-2020-5398 and verify that the dashboard still builds after the change. Done means the vulnerable Spring Framework version is no longer resolved by the dashboard dependency tree.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring-boot
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100