Record summary

CVE-2020-11975 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Apache Unomi

CVE ListApache Unomi 1.0.0 to 1.5.0affected
GitHub AdvisoryBefore 1.5.4 · Fixed in 1.5.4affected

Proofs of concept

1

Repository PoCs

GitHub1135/unomi_exploitRepository PoCby 1135Stars: 6Not analyzed1 file

4.7 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALApache Unomi - Remote Code ExecutionCVSS 9.8

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process, enabling attackers to execute arbitrary code.

Impact

Successful exploitation allows an attacker to execute arbitrary code on the server with the privileges of the Java process, potentially leading to complete system compromise.

Remediation

Update Apache Unomi to version 1.5.2 or later. Disable OGNL scripting in conditions if not required.

WeaknessesCWE-94
AuthorsSourabh-Sahu
Template tagscvecve2020apacheunomirceognloastvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apache:unomi:*:*:*:*:*:*:*:*
Shodan: http.title:"Apache Unomi"
FOFA: title="Apache Unomi"

Source: ProjectDiscovery

References

6