PT-2020-13793 · Apache · Apache Unomi

·

CVE-2020-13942

·

Published

2020-11-18

·

Updated

2022-02-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Unomi versions prior to 1.5.2
Description It is possible to inject malicious OGNL or MVEL scripts into the "/context.json" public endpoint. This issue was partially fixed in version 1.5.1, but a new attack vector was discovered. In Apache Unomi version 1.5.2, scripts are now completely filtered from the input.
Recommendations For versions prior to 1.5.2, upgrade to the latest available version of the 1.5.x release to fix this problem. As a temporary workaround, consider restricting access to the "/context.json" endpoint until a patch is available.

Exploit

Fix

DoS

Special Elements Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13942
GHSA-XP5J-WJ4H-2JQ9

Affected Products

Apache Unomi