CVE Database
/

CVE-2020-13942

Back to search

CVE-2020-13942

Published: Nov 24, 2020

Modified: Feb 13, 2025

PUBLISHED

Description

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.

VendorProductVersions

Apache Software Foundation

Apache Unomi

affected
unspecified - < 1.5.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now