CVE Vulnerabilities

CVE-2021-3396

Published: Feb 17, 2021 | Modified: Jul 12, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.

Affected Software

Name Vendor Start Version End Version
Horizon Opennms 16.0.0 (including) 27.0.3 (including)
Meridian Opennms 2016.1.0 (including) 2016.1.24 (including)
Meridian Opennms 2017.1.0 (including) 2017.1.26 (including)
Meridian Opennms 2018.1.0 (including) 2018.1.25 (excluding)
Meridian Opennms 2019.1.0 (including) 2019.1.16 (excluding)
Meridian Opennms 2020.1.0 (including) 2020.1.5 (excluding)
Newts Opennms * 1.5.3 (excluding)

References