Логотип exploitDog
bind:CVE-2020-1959
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1959

Количество 2

Количество 2

nvd логотип

CVE-2020-1959

почти 6 лет назад

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-vjqw-r3ww-wj2w

больше 4 лет назад

Expression Language Injection in Apache Syncope

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-1959

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code.

CVSS3: 9.8
2%
Низкий
почти 6 лет назад
github логотип
GHSA-vjqw-r3ww-wj2w

Expression Language Injection in Apache Syncope

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу