CVE-2020-11975
Improper Input Validation in Apache Unomi
9.8
CRITICAL
CVSS 3.1
EPSS 29.9%
Description
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
How to fix CVE-2020-11975
To remediate CVE-2020-11975, upgrade the affected package to a fixed version below.
- Maven/org.apache.unomi:unomi—upgrade to 1.5.4 or later
Is CVE-2020-11975 being exploited?
Moderate — EPSS is 29.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.5.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |