[MAVEN:GHSA-853F-X27W-8R74] OpenNMS Horizon RCE via Unsafe Deserialization

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.

Package Affected Version
pkg:maven/org.opennms.core/org.opennms.core.daemon < 26.0.1
ID
MAVEN:GHSA-853F-X27W-8R74
Severity
high
URL
https://github.com/advisories/GHSA-853f-x27w-8r74
Published
2022-05-24T17:17:36
(2 years ago)
Modified
2023-08-21T19:53:39
(13 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.opennms.core/org.opennms.core.daemon org.opennms.core org.opennms.core.daemon < 26.0.1
Fixed pkg:maven/org.opennms.core/org.opennms.core.daemon org.opennms.core org.opennms.core.daemon = 26.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...