Skip to content

Latest commit

 

History

History
 
 

CVE-2020-13942

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

CVE-2020-13942 Apache Unomi RCE

Apache Unomi allows conditions to use OGNL and MVEL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

Affected version: Apache Unomi <= 1.5.1

FOFA query rule: title="Apache Unomi Welcome Page"

Demo