Back to search
CVE-2019-17570
Published: Jan 23, 2020
Modified: Aug 5, 2024
PUBLISHED
Description
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
| Vendor | Product | Versions |
|---|---|---|
Apache | Apache XML-RPC | affected Apache XML-RPC all versions |
References
RHSA-2020:0310
vendor-advisory
DSA-4619
vendor-advisory
FEDORA-2020-1d0635bd71
vendor-advisory
USN-4496-1
vendor-advisory
GLSA-202401-26
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now