Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2020-1953

больше 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2020-1953

больше 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 9
EPSS: Низкий
nvd логотип

CVE-2020-1953

больше 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2020-1953

больше 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML ...

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-7qx4-pp76-vrqh

больше 6 лет назад

Remote code execution in Apache Commons Configuration

CVSS3: 10
EPSS: Низкий
fstec логотип

BDU:2020-05036

больше 6 лет назад

Уязвимость библиотеки библиотеки Apache Commons Configuration, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
7%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 9
7%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
7%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML ...

CVSS3: 10
7%
Низкий
больше 6 лет назад
github логотип
GHSA-7qx4-pp76-vrqh

Remote code execution in Apache Commons Configuration

CVSS3: 10
7%
Низкий
больше 6 лет назад
fstec логотип
BDU:2020-05036

Уязвимость библиотеки библиотеки Apache Commons Configuration, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
7%
Низкий
больше 6 лет назад

Уязвимостей на страницу