← Vulnerability feed

Vulnerability record · CVE-2020-9493 · published 16 June 2021

CVE-2020-9493: Apache chainsaw deserialization of untrusted data vulnerability

Apache · Chainsaw

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

9.8 CVSS 3.1 Critical EPSS 4.6% · top 8.7% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 6.8
4.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9493 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2019-17571Apache Log4j 1.2 SocketServer Deserialization RCELog4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the c…EPSS 69%analysed9.8CVE-2017-5645Apache Log4j 2 socket server deserialization allows remote code executionApache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted ser…EPSS 90%analysed8.8CVE-2022-23307Apache Chainsaw and Log4j 1.2.x Deserialization of Untrusted DataCVE-2022-23307 is a deserialization of untrusted data flaw (CWE-502) that was originally identified in Apache Chainsaw as CVE-2020-9493. The same iss…EPSS 54%analysed8.8CVE-2022-23302Apache Log4j 1.x JMSSink JNDI deserialization remote code executionJMSSink in all versions of Log4j 1.x deserializes untrusted data when an attacker can write to the Log4j configuration or when the configuration refe…EPSS 64%analysed7.5CVE-2023-26464Apache log4j deserialization of untrusted data vulnerability** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2020-9493), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.