Lucene search

K
githubGitHub Advisory DatabaseGHSA-WMFG-55F9-J8HQ
HistoryDec 24, 2020 - 8:49 p.m.

Server-Side Template Injection

2020-12-2420:49:34
CWE-74
GitHub Advisory Database
github.com
46
server-side template injection
browserup proxy
remote code execution
cve-2020-26282
upgrade
version 2.1.2
security advisory
browserup proxy repo
browserup website
support email

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.056

Percentile

93.3%

Impact

A Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been assigned CVE-2020-26282.

Patches

Effective Immediately, all users should upgrade to version 2.1.2 or higher.

Workarounds

None.

References

https://securitylab.github.com/research/bean-validation-RCE

For more information

If you have any questions or comments about this advisory:

Affected configurations

Vulners
Node
com.browserupbrowserup-proxyRange<2.1.2
VendorProductVersionCPE
com.browserupbrowserup-proxy*cpe:2.3:a:com.browserup:browserup-proxy:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.056

Percentile

93.3%

Related for GHSA-WMFG-55F9-J8HQ