CVE-2020-14379
Severity
5.6MEDIUM
EPSS
0.0%
top 88.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 16
Latest updateAug 17
Description
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:HExploitability: 0.8 | Impact: 4.7
Affected Packages2 packages
š“Vulnerability Details
3GHSAā¶
GHSA-f2jp-gmm4-wp64: A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and inforā2022-08-17
CVEListā¶
CVE-2020-14379: A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and inforā2022-08-16
šVendor Advisories
4Oracleā¶
Oracle Oracle GoldenGate Risk Matrix: Security / Application Adapters (jackson-databind, SLF4J, ZooKeeper, Apache Spark) ā CVE-2019-14379ā2020-07-15
Oracleā¶
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (jackson-databind) ā CVE-2019-14379ā2020-04-15
Oracleā¶
Oracle Oracle Communications Applications Risk Matrix: Presence-api (jackson-databind) ā CVE-2019-14379ā2020-01-15