VYPR
High severity7.5NVD Advisory· Published May 29, 2020· Updated Jun 17, 2026

CVE-2020-6937

CVE-2020-6937

Description

A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.

Affected products

4
  • Mulesoft/Muleinferred
    Range: >=3.8.0,<3.9.0 || >=3.9.0,<4.0.0 || >=4.0.0,<4.x (before April 7, 2020)
  • cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:community:*:*:*+ 1 more
    • cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:community:*:*:*range: >=3.8.0,<=3.8.7
    • cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:enterprise:*:*:*range: >=3.8.0,<=3.8.7
  • Range: <=3.9.x, <=4.x, before April 7, 2020

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.