AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-1953

CRITICAL · CVSS 10 EPSS 6.85%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-03-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-1953
Severity
CRITICAL
CVSS
10
EPSS
6.85%
Apache

Original NVD Description

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.