Description

A context.json endpoint of Apache Unomi is vulnerable to MVEL and OGNL expression injection. An attacker could exploit this vulnerability using a specially-crafted expression to execute arbitrary code on the system.

Remediation

Upgrade to the latest version of Apache Unomi (=> 1.5.2)

References

Related Vulnerabilities