← Back

CVE-2020-1964

nvd nist
Published: Apr 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).

Affected (3)

Products: Apache: Heron
1 product
Heron
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 0.20.0-incubating
Version 0.20.1-incubating
Version 0.20.2-incubating

References (10)

Timeline

No history available yet.