KEVIntel
9.8
CVSS
Critical

CVE-2020-13942

PUBLISHED

Remote Code Execution in Apache Unomi

PoC available Remote Low complexity No user interaction
Vendor
Apache Software Foundation
Product
Apache Unomi
Published
Nov 24, 2020
EPSS

Description

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.

nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Proof of concept available

Recorded 2020-11-19 08:22:17 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Jun 09, 2025

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Prodrious/CVE-2020-13942

github · Created 2021-09-05 16:39:19 UTC · 0 stars

yaunsky/Unomi-CVE-2020-13942

github · Created 2020-12-22 02:57:50 UTC · 4 stars

CVE-2020-13942 Apache Unomi 远程代码执行漏洞脚getshell

blackmarketer/CVE-2020-13942

github · Created 2020-11-21 08:48:46 UTC · 3 stars

shifa123/CVE-2020-13942-POC-

github · Created 2020-11-20 23:25:44 UTC · 9 stars

CVE-2020-13942 POC + Automation Script

eugenebmx/CVE-2020-13942

github · Created 2020-11-19 08:22:17 UTC · 28 stars

CVE-2020-13942 unauthenticated RCE POC through MVEL and OGNL injection

lp008/CVE-2020-13942

github · Created 2020-11-18 10:29:47 UTC · 6 stars

Timeline

  • CVE ID Reserved

  • Proof of Concept Exploit Available

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel