Back

CRITICAL

xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response

Published Jan 23, 2020

Description

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 7 provides vulnerable version of xmlrpc via the Optional repository. As the Optional repository is not supported, this issue is not planned to be addressed there. Red Hat Virtualization Manager uses xmlrpc only for internal communication with the scheduler. Since this is a component of the Manager itself, it is not subject to attacker influence and does not represent an attack surface.

Red Hat mitigation

There is no known mitigation other than restricting applications using the Apache XMLRPC client library from sending requests to untrusted XMLRPC servers.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 23, 2020
Updated Aug 5, 2024
Reserved Oct 14, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 16, 2020
GHSA-6VWP-35W3-XPH8