Code Injection in Apache Commons Configuration - CVE-2020-1953

 

Code Injection in Apache Commons Configuration - CVE-2020-1953

Published: March 17, 2020


Vulnerability identifier: #VU26146
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1953
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure configuration of third-party library for parsing YAML files. A remote attacker with ability to pass YAML file to the application can inject and execute arbitrary code on the system.



Affected software

Apache Commons Configuration
Oracle Healthcare Foundation
Sterling Connect Direct File Agent
Jazz Reporting Service
AMQ Broker

How to mitigate CVE-2020-1953

Install updates from vendor's website.

Apache Commons Configuration - update to 2.7
Sterling Connect Direct File Agent - update to 1.4.0.2.8
Jazz Reporting Service - update to 7.0.2 iFix021
AMQ Broker - addressed in versions 7.4.4, 7.7

External References

Related Security Bulletins