Known Vulnerabilities for Unomi by Apache
Listed below are 3 of the newest known vulnerabilities associated with "Unomi" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-31164 json | Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. | 7.5 - HIGH | 2021-05-04 | 2022-10-25 |
| CVE-2020-13942 json | It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1... | 9.8 - CRITICAL | 2020-11-24 | 2023-11-07 |
| CVE-2020-11975 json | Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK th... | 9.8 - CRITICAL | 2020-06-05 | 2023-11-07 |