CVE-2020-5245
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.01% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- dropwizard/dropwizard validation · oracle/blockchain platform
- Source
- security-advisories@github.com
References
- https://beanvalidation.org/2.0/spec/#validationapi-message-defaultmessageinterpolationThird Party Advisory
- https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-interpolation-with-message-expressionsThird Party Advisory
- https://docs.oracle.com/javaee/7/tutorial/jsf-el.htmThird Party Advisory
- https://github.com/dropwizard/dropwizard/commit/28479f743a9d0aab6d0e963fc07f3dd98e8c8236
- https://github.com/dropwizard/dropwizard/commit/d87d1e4f8e20f6494c0232bf8560c961b46db634Patch, Third Party Advisory
- https://github.com/dropwizard/dropwizard/pull/3157Patch, Third Party Advisory
- https://github.com/dropwizard/dropwizard/pull/3160Patch, Third Party Advisory
- https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqfExploit, Third Party Advisory
- https://beanvalidation.org/2.0/spec/#validationapi-message-defaultmessageinterpolationThird Party Advisory
- https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-interpolation-with-message-expressionsThird Party Advisory
- https://docs.oracle.com/javaee/7/tutorial/jsf-el.htmThird Party Advisory
- https://github.com/dropwizard/dropwizard/commit/28479f743a9d0aab6d0e963fc07f3dd98e8c8236
- https://github.com/dropwizard/dropwizard/commit/d87d1e4f8e20f6494c0232bf8560c961b46db634Patch, Third Party Advisory
- https://github.com/dropwizard/dropwizard/pull/3157Patch, Third Party Advisory
- https://github.com/dropwizard/dropwizard/pull/3160Patch, Third Party Advisory
- https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.