GHSA-853f-x27w-8r74

Suggest an improvement
Source
https://github.com/advisories/GHSA-853f-x27w-8r74
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-853f-x27w-8r74/GHSA-853f-x27w-8r74.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-853f-x27w-8r74
Aliases
Published
2022-05-24T17:17:36Z
Modified
2023-11-01T04:51:38.214848Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenNMS Horizon RCE via Unsafe Deserialization
Details

An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.

Database specific
{
    "nvd_published_at": "2020-05-11T16:15:00Z",
    "cwe_ids": [
        "CWE-502"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-13T00:25:26Z"
}
References

Affected packages

Maven / org.opennms.core:org.opennms.core.daemon

Package

Name
org.opennms.core:org.opennms.core.daemon
View open source insights on deps.dev
Purl
pkg:maven/org.opennms.core/org.opennms.core.daemon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
26.0.1