CVE-2020-6958

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yet_another_java_service_wrapper_project:yet_another_java_service_wrapper:12.14:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-01-14 00:15

Updated : 2024-02-28 17:28


NVD link : CVE-2020-6958

Mitre link : CVE-2020-6958

CVE.ORG link : CVE-2020-6958


JSON object : View

Products Affected

yet_another_java_service_wrapper_project

  • yet_another_java_service_wrapper
CWE
CWE-611

Improper Restriction of XML External Entity Reference