
Cloud Vulnerability DB
A community-led vulnerabilities database
A deserialization vulnerability was identified in Apache ShardingSphere (incubator) and assigned CVE-2020-1947. The vulnerability exists in the ShardingSphere's web console which uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. The issue was disclosed on March 11, 2020 (NVD).
The vulnerability stems from the usage of SnakeYAML library in ShardingSphere's web console, specifically in the YAML parsing functionality used for datasource configuration loading. The vulnerability allows for unsafe deserialization of YAML inputs (Apache List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."