Tracker / CVE-2019-17570
CVE-2019-17570
Critical 9.8
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
Affected products and versions
| apache | xml-rpc |
|---|---|
| canonical | ubuntu_linux |
| debian | debian_linux |
| fedoraproject | fedora |
| redhat | software_collections |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.