CVE-2020-6958

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yet_another_java_service_wrapper_project:yet_another_java_service_wrapper:12.14:*:*:*:*:*:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
References () https://github.com/NationalSecurityAgency/ghidra/issues/943 - Exploit, Third Party Advisory () https://github.com/NationalSecurityAgency/ghidra/issues/943 - Exploit, Third Party Advisory
References () https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20affects%20Ghidra%20Server.md - Third Party Advisory () https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20affects%20Ghidra%20Server.md - Third Party Advisory
References () https://sourceforge.net/p/yajsw/bugs/166/ - Exploit, Third Party Advisory () https://sourceforge.net/p/yajsw/bugs/166/ - Exploit, Third Party Advisory

Information

Published : 2020-01-14 00:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-6958

Mitre link : CVE-2020-6958

CVE.ORG link : CVE-2020-6958


JSON object : View

Products Affected

yet_another_java_service_wrapper_project

  • yet_another_java_service_wrapper
CWE
CWE-611

Improper Restriction of XML External Entity Reference