[MAVEN:GHSA-V6FQ-Q792-J46J] Improper Input Validation in Apache Unomi

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

Package Affected Version
pkg:maven/org.apache.unomi/unomi < 1.5.4
Package Fixed Version
pkg:maven/org.apache.unomi/unomi = 1.5.4
ID
MAVEN:GHSA-V6FQ-Q792-J46J
Severity
high
URL
https://github.com/advisories/GHSA-v6fq-q792-j46j
Published
2022-02-09T23:20:47
(2 years ago)
Modified
2023-02-01T05:05:25
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.unomi/unomi org.apache.unomi unomi < 1.5.4
Fixed pkg:maven/org.apache.unomi/unomi org.apache.unomi unomi = 1.5.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...