10
CVSSv3

CVE-2020-1953

Published: 13/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache commons configuration 2.3

apache commons configuration 2.4

apache commons configuration 2.5

apache commons configuration 2.6

apache commons configuration 2.2

oracle database server 12.1.0.2

oracle database server 11.2.0.4

oracle database server 12.2.0.1

oracle database server 18c

oracle database server 19c

oracle healthcare foundation 7.2.0

oracle healthcare foundation 7.2.1

oracle healthcare foundation 7.3.0

oracle healthcare foundation 7.1.1

Vendor Advisories

Debian Bug report logs - #954713 commons-configuration2: CVE-2020-1953 Package: src:commons-configuration2; Maintainer for src:commons-configuration2 is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 22 Mar 2020 14:12:02 UTC Sev ...
Synopsis Important: Red Hat AMQ Broker 744 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 744 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability ...
Synopsis Important: Red Hat AMQ Broker 77 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 77 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: Red Hat Fuse 770 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 76 to 77) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [CVE-2020-1953] Uncontrolled class instantiation when loading YAML files in Apache Commons Configuration <!--X-Subject-Header- ...