High severity7.5NVD Advisory· Published May 29, 2020· Updated Jun 17, 2026
CVE-2020-6937
CVE-2020-6937
Description
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
Affected products
4cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:community:*:*:*+ 1 more
- cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:community:*:*:*range: >=3.8.0,<=3.8.7
- cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:enterprise:*:*:*range: >=3.8.0,<=3.8.7
- Range: <=3.9.x, <=4.x, before April 7, 2020
Patches
Vulnerability mechanics
References
1- help.salesforce.com/articleViewnvdVendor Advisory
News mentions
0No linked articles in our index yet.