alibaba / alibaba/Sentinel

Sentinel 控制台 Spring Framework 反射型文件下载漏洞(CVE-2020-5398)

Open
#2,350 0 comments 0 reactions 0 assignees View on GitHub
dependencies
Dominant language
Java
Stars
23.1k
Forks
8.1k
PR merge metrics
No merged PRs in 30d

Description

## Issue Description

Type: *bug report* or *feature request*

### Describe what happened (or what feature you want)
https://github.com/alibaba/Sentinel/blob/master/sentinel-dashboard/pom.xml
Sentinel 控制台 Spring Framework 反射型文件下载漏洞(CVE-2020-5398)
当前 pom 引入的 springboot版本2.0.5.RELEASE对应的是spring-web-5.0.9.RELEASE
该版本存在一个已发现漏洞

### Describe what you expected to happen

### How to reproduce it (as minimally and precisely as possible)

1.
2.
3.

### Tell us your environment

### Anything else we need to know?

Contributor guide

Open the contributing guide

Research direction

Start with sentinel-dashboard/pom.xml and inspect the Spring Boot and spring-web versions identified in the report. Check which dependency version addresses CVE-2020-5398 and verify that the dashboard still builds after the change. Done means the vulnerable Spring Framework version is no longer resolved by the dashboard dependency tree.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring-boot
Domain
backend, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.