imPC@ndo IT

Tracker / CVE-2019-17570

CVE-2019-17570

Critical 9.8

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.

Affected products and versions

apache xml-rpc
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
redhat software_collections

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References