Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11002

Опубликовано: 10 апр. 2020
Источник: nvd
CVSS3: 8
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability. If you are using a self-validating bean an upgrade to Dropwizard 1.3.21/2.0.3 or later is strongly recommended. The changes introduced in Dropwizard 1.3.19 and 2.0.2 for CVE-2020-5245 unfortunately did not fix the underlying issue completely. The issue has been fixed in dropwizard-validation 1.3.21 and 2.0.3 or later. We strongly recommend upgrading to one of these versions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dropwizard:dropwizard_validation:*:*:*:*:*:*:*:*
Версия до 1.3.21 (исключая)
cpe:2.3:a:dropwizard:dropwizard_validation:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.0.3 (исключая)

EPSS

Процентиль: 79%
0.01256
Низкий

8 High

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-74
CWE-74

Связанные уязвимости

CVSS3: 8
github
почти 6 лет назад

Remote Code Execution (RCE) vulnerability in dropwizard-validation

EPSS

Процентиль: 79%
0.01256
Низкий

8 High

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-74
CWE-74