It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xp5j-wj4h-2jq9 | Injection and Improper Input Validation in Apache Unomi |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:30.019Z
Reserved: 2020-06-08T00:00:00.000Z
Link: CVE-2020-13942
No data.
Status : Modified
Published: 2020-11-24T18:15:11.910
Modified: 2024-11-21T05:02:11.820
Link: CVE-2020-13942
No data.
OpenCVE Enrichment
No data.
Github GHSA