CVE-2020-13942
Remote Code Execution in Apache Unomi
- Published
- Nov 24, 2020
- Updated
- Feb 13, 2025
- Assigning CNA
- apache
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.
Sources
9- apche_unomi_rceExploit
Apache Unomi CVE-2020-13942: RCE Vulnerabilities
- CVE-2020-13942Exploit
CVE-2020-13942 unauthenticated RCE POC through MVEL and OGNL injection
- CVE-2020-13942Exploit
Exploit for Apache Unomi pre-auth RCE (CVE-2020-13942) with a Suricata detection rule for identifying exploitation attempts.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.