Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v6fq-q792-j46j | Improper Input Validation in Apache Unomi |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T11:48:57.089Z
Reserved: 2020-04-21T00:00:00
Link: CVE-2020-11975
No data.
Status : Modified
Published: 2020-06-05T15:15:10.723
Modified: 2024-11-21T04:59:01.647
Link: CVE-2020-11975
No data.
OpenCVE Enrichment
No data.
Github GHSA