QID 983241
QID 983241: Java (maven) Security Update for com.browserup:browserup-proxy (GHSA-wmfg-55f9-j8hq)
Security update has been released for com.browserup:browserup-proxy to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been assigned CVE-2020-26282.
Solution
Effective Immediately, all users should upgrade to version 2.1.2 or higher.Workaround:
None.
None.
Vendor References
- GHSA-wmfg-55f9-j8hq -
github.com/advisories/GHSA-wmfg-55f9-j8hq
CVEs related to QID 983241
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wmfg-55f9-j8hq | com.browserup:browserup-proxy |
|