PT-2020-13793 · Apache · Apache Unomi

Serge Huber

·

Published

2020-11-18

·

Updated

2022-02-10

·

CVE-2020-13942

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Unomi versions prior to 1.5.2
Description It is possible to inject malicious OGNL or MVEL scripts into the "/context.json" public endpoint. This issue was partially fixed in version 1.5.1, but a new attack vector was discovered. In Apache Unomi version 1.5.2, scripts are now completely filtered from the input.
Recommendations For versions prior to 1.5.2, upgrade to the latest available version of the 1.5.x release to fix this problem. As a temporary workaround, consider restricting access to the "/context.json" endpoint until a patch is available.

Exploit

Fix

Special Elements Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13942
GHSA-XP5J-WJ4H-2JQ9

Affected Products

Apache Unomi