CVE-2020-1953 is a critical vulnerability in Apache Commons Configuration versions 2.2 through 2.6, and related Oracle products, stemming from its default use of a third-party YAML parsing library that permits class instantiation. This allows an attacker to execute arbitrary code if a malicious YAML file is loaded from an untrusted source. With a CVSS score of 10.0, this vulnerability presents a critical risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, its high severity warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2CPE matchmatch criteria | cpe:2.3:a:apache:commons_configuration:2.2:*:*:*:*:*:*:* | ||
2.3CPE matchmatch criteria | cpe:2.3:a:apache:commons_configuration:2.3:*:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:apache:commons_configuration:2.4:*:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:apache:commons_configuration:2.5:*:*:*:*:*:*:* | ||
2.6CPE matchmatch criteria | cpe:2.3:a:apache:commons_configuration:2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.