{"id":"CVE-2020-1947","details":"In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.","aliases":["GHSA-v54f-xcmp-43cr"],"modified":"2026-07-08T20:30:23.185749Z","published":"2020-03-11T21:15:11.627Z","references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/r4a61a24c119bd820da6fb02100d286f8aae55c8f9b94a346b9bb27d8%40%3Cdev.shardingsphere.apache.org%3E"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/shardingsphere","events":[{"introduced":"f81f4f03b1dd4b426adf1f29ffe93f9540ce6fc9"},{"last_affected":"78a67e8c088ffc0b6f0e2c7418b0217cdc3bb87d"}],"database_specific":{"cpe":["cpe:2.3:a:apache:shardingsphere:4.0.0:-:*:*:*:*:*:*","cpe:2.3:a:apache:shardingsphere:4.0.0:rc3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.0.0-NA"},{"last_affected":"4.0.0-NA"},{"introduced":"4.0.0-rc3"},{"last_affected":"4.0.0-rc3"}],"source":"CPE_STRING"}}],"versions":["4.0.0-NA","4.0.0-rc3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1947.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}