mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
2.7 KiB
2.7 KiB
CVE-2020-1947
Description
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.
POC
Reference
No PoCs from references.
Github
- https://github.com/0x783kb/Security-operation-book
- https://github.com/0xT11/CVE-POC
- https://github.com/5l1v3r1/CVE-2020-1947
- https://github.com/ARPSyndicate/cvemon
- https://github.com/AdeliaNitzsche/Java-Deserialization-Cheat-Sheet
- https://github.com/BrittanyKuhn/javascript-tutorial
- https://github.com/CnHack3r/Penetration_PoC
- https://github.com/CraigChristmas/CVE-2020-1947
- https://github.com/EchoGin404/-
- https://github.com/EchoGin404/gongkaishouji
- https://github.com/EdwardChristmas/CVE-2020-1947
- https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet
- https://github.com/HexChristmas/CVE-2020-1947
- https://github.com/LubinLew/WEB-CVE
- https://github.com/Mr-xn/Penetration_Testing_POC
- https://github.com/PalindromeLabs/Java-Deserialization-CVEs
- https://github.com/SexyBeast233/SecBooks
- https://github.com/StarkChristmas/CVE-2020-1947
- https://github.com/Tyro-Shan/gongkaishouji
- https://github.com/YIXINSHUWU/Penetration_Testing_POC
- https://github.com/ZTK-009/Penetration_PoC
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/hasee2018/Penetration_Testing_POC
- https://github.com/hectorgie/PoC-in-GitHub
- https://github.com/huike007/penetration_poc
- https://github.com/huike007/poc
- https://github.com/jas502n/CVE-2020-1947
- https://github.com/langligelang/langligelang
- https://github.com/lions2012/Penetration_Testing_POC
- https://github.com/mishmashclone/GrrrDog-Java-Deserialization-Cheat-Sheet
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/password520/Penetration_PoC
- https://github.com/shadowsock5/ShardingSphere_CVE-2020-1947
- https://github.com/soosmile/POC
- https://github.com/threedr3am/learnjavabug
- https://github.com/winterwolf32/CVE-S---Penetration_Testing_POC-
- https://github.com/wsfengfan/CVE-2020-1947
- https://github.com/xuetusummer/Penetration_Testing_POC
- https://github.com/yedada-wei/-
- https://github.com/yedada-wei/gongkaishouji