CVE-2020-15227: Debian Linux

Critical severity, CVSS 9.8. EPSS: 34.4% chance of exploitation in the next 30 days.

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Nette Application: from 2.0.0, before 2.0.19 (fixed in 2.0.19); from 2.1.0, before 2.1.13 (fixed in 2.1.13); from 2.2.0, before 2.2.10 (fixed in 2.2.10); from 2.3.0, before 2.3.14 (fixed in 2.3.14); from 2.4.0, before 2.4.16 (fixed in 2.4.16); from 3.0.0, before 3.0.6 (fixed in 3.0.6)

Published 2020-10-01. Last modified 2026-06-17.