GHSA-c3mp-9vx3-2rvv

Suggest an improvement
Source
https://github.com/advisories/GHSA-c3mp-9vx3-2rvv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c3mp-9vx3-2rvv/GHSA-c3mp-9vx3-2rvv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-c3mp-9vx3-2rvv
Aliases
Published
2022-05-24T17:42:35Z
Modified
2023-11-01T04:55:37.423907Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenNMS Horizon RCE via JEXL2 expression
Details

OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.

Database specific
{
    "nvd_published_at": "2021-02-17T21:15:00Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-11T00:13:01Z"
}
References

Affected packages

Maven / org.opennms:opennms

Package

Name
org.opennms:opennms
View open source insights on deps.dev
Purl
pkg:maven/org.opennms/opennms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
27.0.4

Database specific

{
    "last_known_affected_version_range": "<= 27.0.3"
}

Maven / org.opennms.features:org.opennms.features.measurements

Package

Name
org.opennms.features:org.opennms.features.measurements
View open source insights on deps.dev
Purl
pkg:maven/org.opennms.features/org.opennms.features.measurements

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
27.0.4

Database specific

{
    "last_known_affected_version_range": "<= 27.0.3"
}

Maven / org.opennms:opennms-provision

Package

Name
org.opennms:opennms-provision
View open source insights on deps.dev
Purl
pkg:maven/org.opennms/opennms-provision

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
27.0.4

Database specific

{
    "last_known_affected_version_range": "<= 27.0.3"
}

Maven / org.opennms:opennms-util

Package

Name
org.opennms:opennms-util
View open source insights on deps.dev
Purl
pkg:maven/org.opennms/opennms-util

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
27.0.4

Database specific

{
    "last_known_affected_version_range": "<= 27.0.3"
}