Fiche vulnérabilité
CVE-2020-5245 : faille élevée dropwizard dropwizard validation (CVSS 8.8)
Description
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 24 févr. 2020
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- dropwizard dropwizard validation
- oracle blockchain platform
Références
- Fiche CVE-2020-5245 sur le NVD (NIST)
- beanvalidation.org/2.0/spec/
- docs.jboss.org/hibernate/validator/6…
- docs.oracle.com/javaee/7/tutorial/jsf-el.htm
- github.com/dropwizard/dropwizard/commit/28479f743a9d0aab6…
- github.com/dropwizard/dropwizard/commit/d87d1e4f8e20f6494…
- github.com/dropwizard/dropwizard/pull/3157
- github.com/dropwizard/dropwizard/pull/3160
- github.com/dropwizard/dropwizard/security/advisories/GHSA…