Lucene search

K
cvelistGitHub_MCVELIST:CVE-2020-5245
HistoryFeb 24, 2020 - 5:35 p.m.

CVE-2020-5245 Remote Code Execution (RCE) vulnerability in dropwizard-validation

2020-02-2417:35:20
CWE-74
GitHub_M
www.cve.org

7.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L

8.6 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.4%

Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature.

The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.

CNA Affected

[
  {
    "vendor": "dropwizard",
    "product": "dropwizard-validation",
    "versions": [
      {
        "version": ">= 1.3.0, < 1.3.19",
        "status": "affected"
      },
      {
        "version": ">= 2.0.0, < 2.0.2",
        "status": "affected"
      }
    ]
  }
]

7.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L

8.6 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.4%