CVE-2020-5245
HIGHDropwizard-Validation < 1.3.19 - Remote Code Execution via Java Expression Language Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-5245. PoCs published by LycsHub.
AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2020-5245, demonstrating an RCE vulnerability in Dropwizard's self-validating beans via expression language injection. The exploit leverages a crafted query parameter to execute arbitrary commands through JavaScript evaluation.
Description
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.
Exploits (1)
This repository contains a functional exploit PoC for CVE-2020-5245, demonstrating an RCE vulnerability in Dropwizard's self-validating beans via expression language injection. The exploit leverages a crafted query parameter to execute arbitrary commands through JavaScript evaluation.
References (8)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L