CVE-2020-24379: XEE
Published Sep 9, 2020
·Updated
Last updated 26 August 2025
Other sources
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
— MITRE
Affected Software
5 affected componentsFixes available
Yaws Yaws>=1.81<=2.0.7
Canonical Ubuntu Linux=18.04
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/yaws
2.0.8+dfsg-32.1.1+dfsg-22.2.0+dfsg-2
Remediation
Patch Available
Event History
Sep 9, 2020
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 8, 2024
Data Sourced
via Launchpad·03:19 PM
Description
Feb 23, 2026
Data Sourced
via Ubuntu·09:17 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:18 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-24379?
CVE-2020-24379 has a moderate severity rating due to the potential for XXE injection attacks.
2
How do I fix CVE-2020-24379?
To fix CVE-2020-24379, upgrade Yaws to version 2.0.8 or later.
3
Which versions of Yaws are affected by CVE-2020-24379?
Yaws versions 1.81 to 2.0.7 are affected by CVE-2020-24379.
4
What kind of attack is possible with CVE-2020-24379?
CVE-2020-24379 allows for XML External Entity (XXE) injection attacks.
5
Is CVE-2020-24379 relevant for both Debian and Ubuntu users?
Yes, CVE-2020-24379 is relevant for users of affected Yaws versions on both Debian and Ubuntu systems.