Vulnerability Description
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mulesoft | Mule Runtime | >= 3.8.0, <= 3.8.7 |
References
- https://help.salesforce.com/articleView?id=000353701&language=en_US&type=1&mode=Vendor Advisory
- https://help.salesforce.com/articleView?id=000353701&language=en_US&type=1&mode=Vendor Advisory
FAQ
What is CVE-2020-6937?
CVE-2020-6937 is a vulnerability with a CVSS score of 7.5 (HIGH). A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
How severe is CVE-2020-6937?
CVE-2020-6937 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6937?
Check the references section above for vendor advisories and patch information. Affected products include: Mulesoft Mule Runtime.