CVE-2020-12760

CVE-2020-12760

An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.

Source: CVE-2020-12760

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다