QID 730069
Date Published: 2021-05-05
QID 730069: Apache Unomi Remote Code Execution Vulnerability
Apache Unomi is a REST server that manages user-profiles and events related to the profiles.
Apache Unomi allowed remote attackers to send malicious requests with MVEL and OGNL expressions that could contain arbitrary classes, resulting in Remote Code Execution (RCE) with the privileges of the Unomi application.
Affected Versions:
This vulnerability affects all versions of Apache Unomi prior to 1.5.2
QID Detection Logic (Authenticated):
This QID sends HTTP POST payloads to URL "/context.json".
Successful exploitation of this issue may allow an attacker to execute code.
Solution
Refer to CVE-2020-13942: Remote Code Execution in Apache Unomi for more information about patching this vulnerability.
Vendor References
- CVE-2020-13942 -
unomi.apache.org/security/cve-2020-13942.txt
CVEs related to QID 730069
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-13942 |
|