Looking for the vulnerability index of Invicti's legacy products?
Apache Unomi MVEL RCE (CVE-2020-13942) - Vulnerability Database

Apache Unomi MVEL RCE (CVE-2020-13942)

Description

A context.json endpoint of Apache Unomi is vulnerable to MVEL and OGNL expression injection. An attacker could exploit this vulnerability using a specially-crafted expression to execute arbitrary code on the system.

Remediation

Upgrade to the latest version of Apache Unomi (=> 1.5.2)

Related Vulnerabilities