In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
[
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-005f30d4",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"286320303339749738648665452293868188132",
"257324391713171244827191068720724484049",
"283579218541017171684689494770732785154",
"135831442793539143719651860588652735777"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "client/mysqldump.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-373ae2f3",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"332426695089840650221473020143658201782",
"163213773102795387028649232479366975830",
"283579218541017171684689494770732785154",
"135831442793539143719651860588652735777"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "client/mysqlbinlog.cc"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-4f4bb365",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"332426695089840650221473020143658201782",
"163213773102795387028649232479366975830",
"283579218541017171684689494770732785154",
"4460628275193876015680143352103219177"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "client/mysqlshow.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-59801507",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"259777894433241742399784240979398548086",
"103739100402833506015429806307603891025",
"122411845626865646047612466049667578395",
"196062272697173995273915347355961836570"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "netware/mysql_test_run.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-794b21da",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"332426695089840650221473020143658201782",
"163213773102795387028649232479366975830",
"283579218541017171684689494770732785154",
"49403815870465363966445380698432578282"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "myisam/myisampack.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-7b9a3233",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"191806062182666600507646994983253615409",
"301743209239090784792403320182528337718",
"283579218541017171684689494770732785154",
"28050264574065629034589924804658801911"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "client/mysqlcheck.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-89d00177",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"332426695089840650221473020143658201782",
"163213773102795387028649232479366975830",
"283579218541017171684689494770732785154",
"301995084952544754799980041252067898096"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "client/mysqladmin.cc"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-8fef25ba",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"332426695089840650221473020143658201782",
"163213773102795387028649232479366975830",
"283579218541017171684689494770732785154",
"135831442793539143719651860588652735777"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "client/mysqlimport.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2020-5398-adc4f978",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"length": 3038.0,
"function_hash": "35274163327144436881005907227189575888"
},
"deprecated": false,
"target": {
"file": "netware/mysql_test_run.c",
"function": "setup"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-cc083cf4",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"31124030422733726017064343278784896825",
"309891614808491306136259946086270156839",
"283579218541017171684689494770732785154",
"169289322839281234260500212008461171283"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "myisam/myisamchk.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2020-5398-ea916cc0",
"source": "https://github.com/mysql/mysql-server/commit/a50cc250ffff75eb1a52f9dfeb90a391e1a04cf9",
"digest": {
"line_hashes": [
"88122307925743246448843743527906136474",
"8071850358766640010588713262861304908",
"283579218541017171684689494770732785154",
"147075434473015041838501916981257854123"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "client/mysql.cc"
}
}
]