Company
Date Published
Author
Stefan Achleitner, Jasper Juergensen
Word count
1017
Language
American English
Hacker News points
None

Summary

CVE-2020-36641 is a critical vulnerability in the Java library aXMLRPC, which allows XML-RPC protocol communications over HTTP and was initially believed to be fixed in versions 1.12.1 and higher. However, Dynatrace security researchers discovered that these versions were still susceptible to XML external entity (XXE) attacks, allowing attackers to perform various exploits. After discussions with the developers, aXMLRPC version 1.14.0 was released, effectively addressing the vulnerability. Despite previous claims of resolution from multiple sources, including the National Vulnerability Database and GitHub Security Advisories, the vulnerability remained due to a reversion of initial fixes aimed at solving related issues. This oversight highlights challenges in maintaining accurate vulnerability tracking, which can lead to significant cybersecurity threats or resource allocation issues. Dynatrace ensures its customers are protected by integrating accurate security findings into its platform, emphasizing the importance of reliable threat intelligence in cybersecurity.