[MAVEN:GHSA-WFJ5-2MQR-7JVV] Expression Language Injection in Netflix Conductor

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

Netflix Conductor uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message template being passed to ConstraintValidatorContext.buildConstraintViolationWithTemplate() argument, they will be able to run arbitrary Java code.

Package Affected Version
pkg:maven/com.netflix.conductor/conductor-core <= 2.25.3
Package Fixed Version
pkg:maven/com.netflix.conductor/conductor-core = 2.25.4
ID
MAVEN:GHSA-WFJ5-2MQR-7JVV
Severity
critical
URL
https://github.com/advisories/GHSA-wfj5-2mqr-7jvv
Published
2022-02-10T23:06:57
(2 years ago)
Modified
2023-02-01T05:05:29
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.netflix.conductor/conductor-core com.netflix.conductor conductor-core <= 2.25.3
Fixed pkg:maven/com.netflix.conductor/conductor-core com.netflix.conductor conductor-core = 2.25.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...