Description
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v54f-xcmp-43cr | Deserialization of Untrusted Data in Apache ShardingSphere |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T06:54:00.370Z
Reserved: 2019-12-02T00:00:00.000Z
Link: CVE-2020-1947
No data.
Status : Modified
Published: 2020-03-11T21:15:11.627
Modified: 2024-11-21T05:11:42.750
Link: CVE-2020-1947
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA