Published: 24/11/2020 Updated: 03/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Apache Unomi could allow a remote malicious user to execute arbitrary code on the system, caused by a scripting security issue when using OGNL and MVEL. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code with the permission level of the running Java process.

apache unomi

Description: It is possible to inject malicious OGNL or MVEL scripts into the /contextjson public endpoint This was partially fixed in 151 but a new attack vector was found In version 152 scripts are now completely filtered from the input It is highly recommended to upgrade to the latest available version of the 15x release to fix this p ...

