PT-2026-71386 · Opennms · Opennms Meridian+1
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenNMS Meridian versions prior to 2024.3.12
OpenNMS Meridian versions prior to 2025.0.9
OpenNMS Horizon versions prior to 36.0.3
Description
A JEXL expression sandbox bypass exists in the Measurements REST API. A low-privileged authenticated user can submit a crafted expression to escape the sandbox and load arbitrary Java classes on the server. This could allow an attacker to access confidential information and compromise system integrity. JEXL (Java Expression Language) is a powerful expression language used to evaluate dynamic expressions in Java applications.
Recommendations
Upgrade to Meridian 2024.3.12 or newer.
Upgrade to Meridian 2025.0.9 or newer.
Upgrade to Horizon 36.0.3 or newer.
Ensure the software is installed within private networks and not directly accessible from the Internet.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opennms Horizon
Opennms Meridian