{ "schema_version": "1.4.0", "id": "GHSA-hvq7-7fj2-9jc9", "modified": "2022-05-24T17:20:30Z", "published": "2022-05-24T17:20:30Z", "aliases": [ "CVE-2020-13651" ], "details": "An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java application. By providing an attacker-controlled URL, the client will obtain a rogue JNLP file specifying the installation of malicious JAR archives and executed with full privileges on the client computer.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13651" }, { "type": "WEB", "url": "https://know.bishopfox.com/advisories/digdash-version-2018" } ], "database_specific": { "cwe_ids": [ "CWE-74" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-06-15T19:15:00Z" } }