Beveiligingsadvies

CVE-2020-5245

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-02-24 17:35:20
Laatst bijgewerkt 2024-08-04 08:22:09
Toegewezen door GitHub_M
CVSS-score 7.9
Status PUBLISHED

Beschrijving

Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.