GHSA-wmfg-55f9-j8hq
Server-Side Template Injection
Quick fix
GHSA-wmfg-55f9-j8hq — com.browserup:browserup-proxy: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.1.2</version> for com.browserup:browserup-proxyDetails
### Impact A Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been assigned CVE-2020-26282.
### Patches Effective Immediately, all users should upgrade to version 2.1.2 or higher.
### Workarounds None.
### References https://securitylab.github.com/research/bean-validation-RCE
### For more information If you have any questions or comments about this advisory: * Open an issue in [the BrowserUp Proxy repo](http://github.com/browserup/browserup-proxy) * Contact us via the [BrowserUp website](https://browserup.com) or email us at [support@browserup.com](mailto:support@browserup.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.1.2# pom.xml: bump <version>2.1.2</version> for com.browserup:browserup-proxyReferences
- https://github.com/browserup/browserup-proxy/security/advisories/GHSA-wmfg-55f9-j8hq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-26282[ADVISORY]
- https://github.com/browserup/browserup-proxy/commit/4b38e7a3e20917e5c3329d0d4e9590bed9d578ab[WEB]
- https://github.com/browserup/browserup-proxy/releases/tag/v2.1.2[WEB]
- https://securitylab.github.com/research/bean-validation-RCE[WEB]