CVE-2020-1953
â criticalSummary
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
CVSS Score
10.0
Critical
EPSS Score
2.7
Exploit Probability
Published Date
2020-03-13
First Seen: 2026-01-05
đ Relative Risk Intelligence
This CVE is Extremely High Risk - more severe than 100.0% of all 338,292 vulnerabilities in our database.
#1
Top 5% most severe
Severity Percentile
Last Modified
2024-11-21
Source
NVD đ
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H