VDB
Sign up
CRITICAL9.1

GHSA-w48j-pp7j-fj55

Valtimo scripting engine can be used to gain access to sensitive data or resources

Quick fix

GHSA-w48j-pp7j-fj55 — com.ritense.valtimo:core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>12.16.0.RELEASE</version> for com.ritense.valtimo:core

Details

### Impact Any admin that can create or modify and execute process-definitions could gain access to sensitive data or resources.

This includes but is not limited to: - Running executables on the application host - Inspecting and extracting data from the host environment or application properties - Spring beans (application context, database pooling)

### Attack requirements The following conditions have to be met in order to perform this attack: - The user must be logged in - The user must have the admin role (ROLE_ADMIN), which is required to change process definitions - The user must have some knowledge about running scripts via a the Camunda/Operator engine

### Patches Version 12.16.0 and 13.1.2 have been patched. It is strongly advised to upgrade.

### Workarounds If no scripting is needed in any of the processes, it could be possible to disable it altogether via the `ProcessEngineConfiguration`: ``` @Component class NoScriptEnginePlugin : ProcessEnginePlugin { override fun preInit(processEngineConfiguration: ProcessEngineConfigurationImpl) {}

override fun postInit(processEngineConfiguration: ProcessEngineConfigurationImpl) { processEngineConfiguration.scriptEngineResolver = null }

override fun postProcessEngineBuild(processEngine: ProcessEngine) {} } ``` Warning: this workaround could lead to unexpected side-effects. Please test thoroughly.

### References - Valtimo 12 and lower: [Camunda Scripting](https://docs.camunda.org/manual/latest/user-guide/process-engine/scripting/#custom-scriptengineresolver) - Valtimo 13 and higher: [Operaton Scripting](https://docs.operaton.org/docs/documentation/user-guide/process-engine/scripting)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.ritense.valtimo:core
Introduced in: 0Fixed in: 12.16.0.RELEASE
Fix# pom.xml: bump <version>12.16.0.RELEASE</version> for com.ritense.valtimo:core
Maven/com.ritense.valtimo:core
Introduced in: 13.0.0.RELEASEFixed in: 13.1.2.RELEASE
Fix# pom.xml: bump <version>13.1.2.RELEASE</version> for com.ritense.valtimo:core

References