VDB
Sign up
CRITICAL10.0

GHSA-wmfg-55f9-j8hq

Server-Side Template Injection

Quick fix

GHSA-wmfg-55f9-j8hq — com.browserup:browserup-proxy: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.1.2</version> for com.browserup:browserup-proxy

Details

### Impact A Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been assigned CVE-2020-26282.

### Patches Effective Immediately, all users should upgrade to version 2.1.2 or higher.

### Workarounds None.

### References https://securitylab.github.com/research/bean-validation-RCE

### For more information If you have any questions or comments about this advisory: * Open an issue in [the BrowserUp Proxy repo](http://github.com/browserup/browserup-proxy) * Contact us via the [BrowserUp website](https://browserup.com) or email us at [support@browserup.com](mailto:support@browserup.com)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.browserup:browserup-proxy
Introduced in: 0Fixed in: 2.1.2
Fix# pom.xml: bump <version>2.1.2</version> for com.browserup:browserup-proxy

References