CVE-2020-13942
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.
- Affected products
- Apache Unomi
- Apache Unomi
- < 1.5.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 68.4% (99th percentile)
- Weakness
- CWE-74, CWE-20
- NVD status
- Modified
- Published
- 2020-11-24
CVE-2020-13942 at NVD
8 known exploits for CVE-2020-13942
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Authentication Bypass Using an Alternate Path or Channel in Solarwinds Orion_Platform
Exploit for Improper Input Validation in Apache Unomi
Exploit for Improper Input Validation in Apache Unomi
Exploit for Improper Input Validation in Apache Unomi
Exploit for CVE-2020-11975
Exploit for Improper Input Validation in Apache Unomi
Exploit for Improper Input Validation in Apache Unomi
Exploit for Improper Input Validation in Apache Unomi