Back to search
CVE-2020-1947
Published: Mar 11, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache ShardingSphere(incubator) | affected 4.0.0-RC3affected 4.0.0 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now