CVE-2020-1953: Apache Commons Configuration

Critical severity, CVSS 10.0. EPSS: 6.8% chance of exploitation in the next 30 days.

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.

Affected products

  • Apache Commons Configuration: version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only; version 2.6 only
  • Oracle Database Server: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only; version 19c only
  • Oracle Healthcare Foundation: version 7.1.1 only; version 7.2.0 only; version 7.2.1 only; version 7.3.0 only

Published 2020-03-13. Last modified 2026-06-17.