Lucene search

K
redhatcveRedhat.comRH:CVE-2020-1953
HistoryMar 25, 2020 - 2:39 a.m.

CVE-2020-1953

2020-03-2502:39:18
redhat.com
access.redhat.com
17

0.006 Low

EPSS

Percentile

79.2%

A flaw was found in the Apache Commons Configuration, where it uses a third-party library to process YAML files, which by default, allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. If a YAML file was loaded from an untrusted source, it could load and execute code out of the control of the host application.

Mitigation

There is currently no mitigation available for this vulnerability.