Логотип exploitDog
bind:CVE-2020-1953
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1953

Количество 6

Количество 6

ubuntu логотип

CVE-2020-1953

почти 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2020-1953

почти 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 9
EPSS: Низкий
nvd логотип

CVE-2020-1953

почти 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2020-1953

почти 6 лет назад

Apache Commons Configuration uses a third-party library to parse YAML ...

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-7qx4-pp76-vrqh

больше 5 лет назад

Remote code execution in Apache Commons Configuration

CVSS3: 10
EPSS: Низкий
fstec логотип

BDU:2020-05036

почти 6 лет назад

Уязвимость библиотеки библиотеки Apache Commons Configuration, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
3%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 9
3%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS3: 10
3%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-1953

Apache Commons Configuration uses a third-party library to parse YAML ...

CVSS3: 10
3%
Низкий
почти 6 лет назад
github логотип
GHSA-7qx4-pp76-vrqh

Remote code execution in Apache Commons Configuration

CVSS3: 10
3%
Низкий
больше 5 лет назад
fstec логотип
BDU:2020-05036

Уязвимость библиотеки библиотеки Apache Commons Configuration, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
3%
Низкий
почти 6 лет назад

Уязвимостей на страницу