CVE-2020-24379: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
Affected products
- Canonical Ubuntu Linux: version 18.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Yaws Yaws: from 1.81, up to and including 2.0.7
Published 2020-09-09. Last modified 2026-06-17.