Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-05-14T20:39:25
Updated: 2024-08-03T23:17:28.916Z
Reserved: 2021-05-05T00:00:00
Link: CVE-2021-32054
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-05-14T21:15:07.490
Modified: 2021-05-27T19:01:57.617
Link: CVE-2021-32054
Redhat
No data.