Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22706
HistoryMar 16, 2020 - 4:22 a.m.

Arbitrary Code Execution

2020-03-1604:22:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.006 Low

EPSS

Percentile

79.2%

commons-configuration2 is vulnerable to arbitrary code execution. The library allows instantiation of classes when parsing YAML files. This allows an attacker to execute arbitrary code via a malicious YAML file containing special statements that creates arbitrary Java objects.

CPENameOperatorVersion
apache commons configurationle2.6