Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25488
HistoryMay 26, 2020 - 5:54 a.m.

Arbitrary Code Execution

2020-05-2605:54:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.006 Low

EPSS

Percentile

79.2%

commons-configuration2 is vulnerable to arbitrary code execution. The package uses a third-party library that, by default, allows the instantiation of arbitrary classes to parse if the YAML contains special statements. This allows an attacker to execute arbitrary code on the host application if the YAML file is loaded from an untrusted source.

CPENameOperatorVersion
apache commons configurationle2.6