Vulnerability Description
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yet Another Java Service Wrapper Project | Yet Another Java Service Wrapper | 12.14 |
Related Weaknesses (CWE)
References
- https://github.com/NationalSecurityAgency/ghidra/issues/943ExploitThird Party Advisory
- https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%EThird Party Advisory
- https://sourceforge.net/p/yajsw/bugs/166/ExploitThird Party Advisory
- https://github.com/NationalSecurityAgency/ghidra/issues/943ExploitThird Party Advisory
- https://github.com/purpleracc00n/Exploits-and-PoC/blob/master/XXE%20in%20YAJSW%EThird Party Advisory
- https://sourceforge.net/p/yajsw/bugs/166/ExploitThird Party Advisory
FAQ
What is CVE-2020-6958?
CVE-2020-6958 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially c...
How severe is CVE-2020-6958?
CVE-2020-6958 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-6958?
Check the references section above for vendor advisories and patch information. Affected products include: Yet Another Java Service Wrapper Project Yet Another Java Service Wrapper.