add CVE-2020-13942

This commit is contained in:
tardc 2020-11-26 18:31:12 +08:00
parent b23ae4f252
commit 4253125256
2 changed files with 11 additions and 0 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 569 KiB

View File

@ -0,0 +1,11 @@
# CVE-2020-13942 Apache Unomi RCE
Apache Unomi allows conditions to use OGNL and MVEL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
**Affected version**: Apache Unomi <= 1.5.1
**[FOFA](https://fofa.so/result?q=title%3D%22Apache+Unomi+Welcome+Page%22&qbase64=dGl0bGU9IkFwYWNoZSBVbm9taSBXZWxjb21lIFBhZ2Ui&file=&file=) query rule**: title="Apache Unomi Welcome Page"
# Demo
![](CVE-2020-13942.gif)