CVEFinder.io

CVE-2020-1953

⛔ critical
🔍 Scan for this CVE
Summary

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

CVSS Score
10.0
Critical
EPSS Score
2.7
Exploit Probability
Published Date
2020-03-13
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Extremely High Risk - more severe than 100.0% of all 338,292 vulnerabilities in our database.

#1
Top 5% most severe
Severity Percentile
Last Modified 2024-11-21
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

đŸ“Ļ Affected Products 14

🔗 References 4

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-46833 ⛔ critical 9.0 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-46834 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-46835 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-45205 đŸ”ļ medium 5.3 0.1 Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config... 2026-05-14
CVE-2026-34312 â„šī¸ low 2.4 0.0 Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea... 2026-04-21
CVE-2026-21939 âš ī¸ high 7.0 0.0 Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0... 2026-01-20
These CVEs affect the same products