Product
apache unomi
3 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-31164
CVE-2020-13942
CVE-2020-11975
< 1.5.5
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
>= 1.5.0 and < 1.5.2
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1
< 1.5.1
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that co