1 results (0.000 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser. Firely/Incendi Spark versiones anteriores a 1.5.5-r4, carece de encabezados Content-Disposition en determinadas situaciones, lo que puede causar a unos archivos diseñados ser enviados a clientes de manera que son procesados directamente en el navegador web de la víctima • https://github.com/FirelyTeam/spark/commit/9c79320059f92d8aa4fbd6cc4fa8f9d5d6ba9941 https://github.com/FirelyTeam/spark/compare/v1.5.4-r4...v1.5.5-r4 https://github.com/FirelyTeam/spark/releases/tag/v1.5.5-r4 • CWE-706: Use of Incorrectly-Resolved Name or Reference •