CVE-2020-6958
CRITICAL 9.1EPSS 2.4%
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
- CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H - CVSS v2.0
- 6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P - EPSS
- 2.35% chance of exploitation in the next 30 days, 83th percentile
- Published
- 2020-01-13
- Updated
- 2024-08-04
Proof-of-concept exploits (3)
- NationalSecurityAgency/ghidra/issues/943
- purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%E2%80%99s%20JnlpSupport%20aff…
- https://sourceforge.net/p/yajsw/bugs/166/