CVE-2020-24379
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- Affected products
- Ubuntu, Yaws Webserver
- Yaws
- ≤ 2.0.7
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 3.4% (88th percentile)
- Weakness
- CWE-611
- NVD status
- Modified
- Published
- 2020-09-09
CVE-2020-24379 at NVD
1 known exploit for CVE-2020-24379
Proof-of-concept code and exploit modules indexed by Sploitus