PT-2025-33693 · Apache+1 · Apache Commons Ognl+1

Yyjlf

·

Published

2025-08-18

·

Updated

2025-10-28

·

CVE-2025-53192

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache Commons OGNL (affected versions not specified)
Description: An improper neutralization of expression/command delimiters issue exists in Apache Commons OGNL. The OGNL engine, when used with the Ognl.getValue API, parses and evaluates expressions, offering capabilities like method access and invocation. Existing restrictions attempting to block dangerous classes and methods are not comprehensive, potentially allowing attackers to bypass them using uncovered class objects and achieve arbitrary code execution.
Recommendations: As this project is retired and no fix is planned, users are recommended to find an alternative or restrict access to the instance to trusted users.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-53192
OPENSUSE-SU-2025:15567-1
OPENSUSE-SU-2025:15568-1
SUSE-SU-2025:03285-1
SUSE-SU-2025:3825-1
SUSE-SU-2025:3827-1
SUSE-SU-2025:3839-1

Affected Products

Apache Commons Ognl
Debian