PoC Index

CVE-2020-11975

HIGH 10.0EPSS 29.9%

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
29.89% chance of exploitation in the next 30 days, 98th percentile
Nuclei
critical · CWE-94
Published
2020-06-05
Updated
2024-08-04

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related