org.apache.unomi:unomi
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.unomi:unomipage 1 of 1
- CVE-2020-11975CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.5.42020-06-05
vulnerable: 1.0.0-incubating ... 1.5.3 (8 versions)
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
- CVE-2020-13942CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.5.22020-11-24
vulnerable: 1.0.0-incubating ... 1.5.1 (6 versions)
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the…
- CVE-2021-31164HIGHCVSS 7.5EG 7.5✓ Fixed in 1.5.52021-05-04
vulnerable: 1.0.0-incubating ... 1.5.4 (9 versions)
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
Check whether org.apache.unomi:unomi is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.unomi:unomi CVEs against the assets you own.
Start Free Scan →