CVE Database
/

CVE-2020-1947

Back to search

CVE-2020-1947

Published: Mar 11, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.

VendorProductVersions

Apache Software Foundation

Apache ShardingSphere(incubator)

affected
4.0.0-RC3
affected
4.0.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now