PT-2025-33693 · Apache+1 · Apache Commons Ognl+1
Yyjlf
·
Published
2025-08-18
·
Updated
2025-10-28
·
CVE-2025-53192
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache Commons OGNL (affected versions not specified)
Description:
An improper neutralization of expression/command delimiters issue exists in Apache Commons OGNL. The OGNL engine, when used with the
Ognl.getValue API, parses and evaluates expressions, offering capabilities like method access and invocation. Existing restrictions attempting to block dangerous classes and methods are not comprehensive, potentially allowing attackers to bypass them using uncovered class objects and achieve arbitrary code execution.Recommendations:
As this project is retired and no fix is planned, users are recommended to find an alternative or restrict access to the instance to trusted users.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Commons Ognl
Debian