Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2020-24379
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2020-24379
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-24379.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-24379
Downstream
DEBIAN-CVE-2020-24379
DLA-2384-1
DSA-4773-1
UBUNTU-CVE-2020-24379
USN-4569-1
Published
2020-09-09T19:15:21.087Z
Modified
2025-11-14T10:58:34.861593Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
References
https://vuln.be/post/yaws-xxe-and-shell-injections/
https://github.com/erlyaws/yaws/commits/master
https://github.com/vulnbe/poc-yaws-dav-xxe
https://lists.debian.org/debian-lts-announce/2020/09/msg00022.html
https://packetstormsecurity.com/files/159106/Yaws-2.0.7-XML-Injection-Command-Injection.html
https://usn.ubuntu.com/4569-1/
https://www.debian.org/security/2020/dsa-4773
Affected packages
Git
/
github.com/erlyaws/yaws
Affected ranges
Type
GIT
Repo
https://github.com/erlyaws/yaws
Events
Introduced
54139d81eba1c9200c6b07f65bdba03a301cd3c2
Last affected
c5aa1e300105578f3c3c025b367f4d2725ae5b5d
Affected versions
yaws-1.*
yaws-1.81
yaws-1.82
yaws-1.83
yaws-1.84
yaws-1.85
yaws-1.86
yaws-1.87
yaws-1.88
yaws-1.89
yaws-1.90
yaws-1.91
yaws-1.92
yaws-1.93
yaws-1.94
yaws-1.95
yaws-1.96
yaws-1.97
yaws-1.98
yaws-1.99
yaws-2.*
yaws-2.0
yaws-2.0.2
yaws-2.0.3
yaws-2.0.4
yaws-2.0.5
yaws-2.0.6
yaws-2.0.7
Other
yaws-erlang-18
CVE-2020-24379 - OSV