CVE-2020-1953
published 2020-03-13CVE-2020-1953: Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special…
PriorityP262critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
6.68%
93.1th percentile
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_commons_configuration | — | — |
| apache | apache_commons_configuration | — | — |
| apache | apache_commons_configuration | — | — |
| apache | apache_commons_configuration | — | — |
| apache | apache_commons_configuration | — | — |
| apache | commons_configuration | — | — |
| apache | commons_configuration | — | — |
| apache | commons_configuration | — | — |
| apache | commons_configuration | — | — |
| apache | commons_configuration | — | — |
| debian | commons-configuration2 | < commons-configuration2 2.7-1 (bookworm) | commons-configuration2 2.7-1 (bookworm) |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | healthcare_foundation | — | — |
| oracle | healthcare_foundation | — | — |
| oracle | healthcare_foundation | — | — |
| oracle | healthcare_foundation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: YAML file loaded from an untrusted source containing special statements that instantiate arbitrary classes — look for YAML payloads with class instantiation directives (e.g., SnakeYAML '!!' tags) being parsed by Apache Commons Configuration 2.2–2.6 ↗
- →Upstream patch commit to diff for detection of the fix (SafeConstructor enforcement): https://github.com/apache/commons-configuration/commit/add7375cf37fd316d4838c6c56b054fc293b4641 ↗
- ·Only Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, and 2.6 are affected; packages that do not include YAML configuration support are NOT affected regardless of version. ↗
- ·Several Red Hat packages are unaffected because they do not include support for YAML configurations: apache-commons-configuration (RHEL 7), apache-commons-configuration (Red Hat Enterprise Virtualization), rh-maven35-apache-commons-configuration (Red Hat Software Collections), commons-configuration (Red Hat Gluster Storage). ↗
- ·There is currently no mitigation available for this vulnerability; the fix requires upgrading to version 2.7 or later. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_oracle10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Health Sciences Applications Risk Matrix: Self Service Analytics (Apache Commons Configuration) — CVE-2020-1953
vendor_oracle·2020-10-15·CVSS 10.0
CVE-2020-1953 [CRITICAL] Oracle Oracle Health Sciences Applications Risk Matrix: Self Service Analytics (Apache Commons Configuration) — CVE-2020-1953
Oracle Oracle Health Sciences Applications Risk Matrix: Self Service Analytics (Apache Commons Configuration) vulnerability
CVE: CVE-2020-1953
CVSS: 10.0
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Red Hat
apache-commons-configuration: uncontrolled class instantiation when loading YAML files
vendor_redhat·2020-03-13·CVSS 10.0
CVE-2020-1953 [CRITICAL] CWE-20 apache-commons-configuration: uncontrolled class instantiation when loading YAML files
apache-commons-configuration: uncontrolled class instantiation when loading YAML files
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
A flaw was found in the Apache Commons Configuration, where it uses a third-party library to process YAML files, which by default, allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change t
Debian
CVE-2020-1953: commons-configuration2 - Apache Commons Configuration uses a third-party library to parse YAML files whic...
vendor_debian·2020·CVSS 10.0
CVE-2020-1953 [CRITICAL] CVE-2020-1953: commons-configuration2 - Apache Commons Configuration uses a third-party library to parse YAML files whic...
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
Scope: local
bookworm: resolved (fixed in 2.7-1)
bullseye: resolved (fixed in 2.7-1)
forky: resolved (fixed in 2.7-1)
sid: resolved (fixed in 2.7-1)
trixie: resolved (fixed in 2.7-1)
OSV
Remote code execution in Apache Commons Configuration
osv·2020-05-21
CVE-2020-1953 [CRITICAL] Remote code execution in Apache Commons Configuration
Remote code execution in Apache Commons Configuration
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
GHSA
Remote code execution in Apache Commons Configuration
ghsa·2020-05-21
CVE-2020-1953 [CRITICAL] CWE-20 Remote code execution in Apache Commons Configuration
Remote code execution in Apache Commons Configuration
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
OSV
CVE-2020-1953: Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes
osv·2020-03-13·CVSS 10.0
CVE-2020-1953 [CRITICAL] CVE-2020-1953: Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1953 apache-commons-configuration2: apache-commons-configuration: uncontrolled class instantiation when loading YAML files [fedora-all]
bugzilla·2020-03-19·CVSS 10.0
CVE-2020-1953 [CRITICAL] CVE-2020-1953 apache-commons-configuration2: apache-commons-configuration: uncontrolled class instantiation when loading YAML files [fedora-all]
CVE-2020-1953 apache-commons-configuration2: apache-commons-configuration: uncontrolled class instantiation when loading YAML files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files
bugzilla·2020-03-19·CVSS 10.0
CVE-2020-1953 [CRITICAL] CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files
CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
References:
https://lists.apache.org/thread.html/d0e00f2e147a9e9b13a6829133092f349b2882bf6860397368a52600@%3Cannounce.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rde2186ad6ac0d6ed8d51af7509244adcf1ce0f9a3b7e1d1dd3b64676@%3Ccommits.camel.apache.org%3E
Discu
Bugzilla
CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files [fedora-all]
bugzilla·2020-03-19·CVSS 10.0
CVE-2020-1953 [CRITICAL] CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files [fedora-all]
CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
https://lists.apache.org/thread.html/d0e00f2e147a9e9b13a6829133092f349b2882bf6860397368a52600%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r16a2e949e35780c8974cf66104e812410f3904f752df6b66bf292269%40%3Ccommits.servicecomb.apache.org%3Ehttps://lists.apache.org/thread.html/rde2186ad6ac0d6ed8d51af7509244adcf1ce0f9a3b7e1d1dd3b64676%40%3Ccommits.camel.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://lists.apache.org/thread.html/d0e00f2e147a9e9b13a6829133092f349b2882bf6860397368a52600%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r16a2e949e35780c8974cf66104e812410f3904f752df6b66bf292269%40%3Ccommits.servicecomb.apache.org%3Ehttps://lists.apache.org/thread.html/rde2186ad6ac0d6ed8d51af7509244adcf1ce0f9a3b7e1d1dd3b64676%40%3Ccommits.camel.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-03-13
Published