CVE-2020-11002
Summary
| CVE | CVE-2020-11002 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-10 19:15:00 UTC |
| Updated | 2020-04-13 15:17:00 UTC |
| Description | dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability. If you are using a self-validating bean an upgrade to Dropwizard 1.3.21/2.0.3 or later is strongly recommended. The changes introduced in Dropwizard 1.3.19 and 2.0.2 for CVE-2020-5245 unfortunately did not fix the underlying issue completely. The issue has been fixed in dropwizard-validation 1.3.21 and 2.0.3 or later. We strongly recommend upgrading to one of these versions. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Policy · dropwizard/dropwizard · GitHub |
MISC |
github.com |
Third Party Advisory |
| Hibernate Validator 6.1.4.Final - Jakarta Bean Validation Reference Implementation: Reference Guide |
MISC |
docs.jboss.org |
Third Party Advisory |
| Remote Code Execution (RCE) vulnerability in dropwizard-validation <2.0.2 · Advisory · dropwizard/dropwizard · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Disable message interpolation in ConstraintViolations by default (#3208) · dropwizard/dropwizard@d5a512f · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Remote Code Execution (RCE) vulnerability in dropwizard-validation <2.0.3 · Advisory · dropwizard/dropwizard · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| Disable message interpolation in ConstraintViolations by default by joschi · Pull Request #3209 · dropwizard/dropwizard · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Disable message interpolation in ConstraintViolations by default by joschi · Pull Request #3208 · dropwizard/dropwizard · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982421 Java (maven) Security Update for io.dropwizard:dropwizard-validation (GHSA-8jpx-m2wh-2v34)