Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v6fq-q792-j46j | Improper Input Validation in Apache Unomi |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T11:48:57.089Z
Reserved: 2020-04-21T00:00:00
Link: CVE-2020-11975
No data.
Status : Modified
Published: 2020-06-05T15:15:10.723
Modified: 2024-11-21T04:59:01.647
Link: CVE-2020-11975
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA