GHSA-c3mp-9vx3-2rvv

    Dashboard / Vulnerabilities / GHSA-c3mp-9vx3-2rvv

    GHSA-c3mp-9vx3-2rvv

    Published: 24 May 2022Last Modified: 8 Nov 2023
    Aliases:

    Summary: OpenNMS Horizon RCE via JEXL2 expression

    Details: OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.

    Affected packages

    Package

    Name: org.opennms:opennms

    Purl: pkg:maven/org.opennms/opennms

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 16.0.0
    Fixed -27.0.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-c3mp-9vx3-2rvv | CVE-DB