Yaws 2.0.5

CPE Details

Yaws 2.0.5
2.0.5
2020-05-18
12h05 +00:00
2020-05-18
12h05 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:yaws:yaws:2.0.5:*:*:*:*:*:*:*

Informations

Vendor

yaws

Product

yaws

Version

2.0.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-24916 2020-09-09 16h10 +00:00 CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
9.8
Critical
CVE-2020-24379 2020-09-09 16h10 +00:00 WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
9.8
Critical
CVE-2020-12872 2020-05-15 16h20 +00:00 yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.
5.5
Medium