High severity7.9NVD Advisory· Published Feb 24, 2020· Updated Jun 17, 2026
CVE-2020-5245
CVE-2020-5245
Description
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature.
The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.dropwizard:dropwizard-validationMaven | >= 1.3.0-rc1, < 1.3.19 | 1.3.19 |
io.dropwizard:dropwizard-validationMaven | >= 2.0.0, < 2.0.2 | 2.0.2 |
Affected products
4cpe:2.3:a:dropwizard:dropwizard_validation:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dropwizard:dropwizard_validation:*:*:*:*:*:*:*:*range: <1.3.19
- (no CPE)range: >= 1.3.0, < 1.3.19
- cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*Range: <21.1.2
Patches
Vulnerability mechanics
References
11- github.com/dropwizard/dropwizard/commit/d87d1e4f8e20f6494c0232bf8560c961b46db634nvdPatchThird Party AdvisoryWEB
- github.com/dropwizard/dropwizard/pull/3157nvdPatchThird Party AdvisoryWEB
- github.com/dropwizard/dropwizard/pull/3160nvdPatchThird Party AdvisoryWEB
- github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqfnvdExploitThird Party AdvisoryWEB
- beanvalidation.org/2.0/spec/nvdThird Party AdvisoryWEB
- docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/nvdThird Party AdvisoryWEB
- docs.oracle.com/javaee/7/tutorial/jsf-el.htmnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-3mcp-9wr4-cjqfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-5245ghsaADVISORY
- github.com/dropwizard/dropwizard/commit/28479f743a9d0aab6d0e963fc07f3dd98e8c8236nvdWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlghsaWEB
News mentions
0No linked articles in our index yet.