Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xp5j-wj4h-2jq9

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Injection and Improper Input Validation in Apache Unomi

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.

Пакеты

Наименование

org.apache.unomi:unomi

maven
Затронутые версииВерсия исправления

< 1.5.2

1.5.2

EPSS

Процентиль: 100%
0.9432
Критический

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.

EPSS

Процентиль: 100%
0.9432
Критический

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-74