ZeroHour

CVE-2020-6958

PoC ×2
CVSS 3.1
9.1 critical
EPSS
2%p83
Published
()
Modified
Description

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.

Vendors
yet another java service wrapper project
Products
yet another java service wrapper
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.