CVE-2019-17570Deserialization of Untrusted Data in Apache Xml-rpc

Severity
9.8CRITICALNVD
EPSS
70.5%
top 1.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateSep 15

Description

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDapache/xml-rpc4 versions+3
CVEListV5apache/apache_xml-rpcApache XML-RPC all versions

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 31, 32, Ubuntu Linux 16.04, 18.04

Patches

🔴Vulnerability Details

5
OSV
Apache XML-RPC vulnerability2020-09-15
GHSA
Insecure Deserialization in Apache XML-RPC2020-06-10
OSV
Insecure Deserialization in Apache XML-RPC2020-06-10
OSV
CVE-2019-17570: An untrusted deserialization was found in the org2020-01-23
CVEList
CVE-2019-17570: An untrusted deserialization was found in the org2020-01-23

📋Vendor Advisories

2
Ubuntu
Apache XML-RPC vulnerability2020-09-15
Red Hat
xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response2020-01-16

💬Community

2
Bugzilla
CVE-2019-17570 xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response [fedora-all]2020-01-16
Bugzilla
CVE-2019-17570 xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response2019-11-21
CVE-2019-17570 — Deserialization of Untrusted Data | cvebase