Vulnerabilities > CVE-2020-24379 - XXE vulnerability in multiple products

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
yaws
debian
canonical
CWE-611
critical

Summary

WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.