Description
A context.json endpoint of Apache Unomi is vulnerable to MVEL and OGNL expression injection. An attacker could exploit this vulnerability using a specially-crafted expression to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Apache Unomi (=> 1.5.2)
References
Related Vulnerabilities
Python Improper Input Validation Vulnerability (CVE-2023-24329)
WordPress 2.6.1 Lost Password SQL Column Truncation Unauthorized Access Vulnerability (0.71 - 2.6.1)
WordPress Plugin ProfileGrid-User Profiles, Groups and Communities Remote Code Execution (2.8.5)
WordPress Plugin Auto Attachments TimThumb Arbitrary File Upload (0.3)