« Volver al listado

CVE-2020-6937

Estado: ModificadaAlta (7.5)—

A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-6937",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@salesforce.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "MuleSoft Mule CE/EE",
          "versions": [
            {
              "status": "affected",
              "version": "3.8.x"
            },
            {
              "status": "affected",
              "version": "3.9.x"
            },
            {
              "status": "affected",
              "version": "4.x"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-05-29T22:15:10.553",
  "references": [
    {
      "url": "https://help.salesforce.com/articleView?id=000353701&language=en_US&type=1&mode=1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@salesforce.com"
    },
    {
      "url": "https://help.salesforce.com/articleView?id=000353701&language=en_US&type=1&mode=1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de Denegación de Servicio en MuleSoft Mule CE/EE versiones 3.8.x, 3.9.x y 4.x publicada antes del 7 de abril de 2020, podría permitir a atacantes remotos enviar datos que pueden conllevar al agotamiento de recursos."
    }
  ],
  "lastModified": "2026-06-17T03:23:59.973",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "527BE337-26A2-4E94-B133-379F69C0048B",
              "versionEndIncluding": "3.8.7",
              "versionStartIncluding": "3.8.0"
            },
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E77E93A9-0721-48D3-AA7E-7BC449602F46",
              "versionEndIncluding": "3.8.7",
              "versionStartIncluding": "3.8.0"
            },
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7808013B-7B73-4079-9A55-E058095983BA",
              "versionEndIncluding": "3.9.4",
              "versionStartIncluding": "3.9.0"
            },
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D2E1C69-A73F-4AB2-9E51-830A8A0EF893",
              "versionEndIncluding": "3.9.4",
              "versionStartIncluding": "3.9.0"
            },
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88C1A670-A99C-4183-B887-F6268A4C758E",
              "versionEndIncluding": "4.3.0",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "455F29FB-A4C5-427D-9B40-AC6BB83B48DD",
              "versionEndIncluding": "4.3.0",
              "versionStartIncluding": "4.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@salesforce.com"
}