CVE-2020-13942 is a remote code execution vulnerability in Apache Unomi affecting the public /context.json endpoint. The flaw allows an attacker to inject malicious OGNL or MVEL expressions through request input processed by that endpoint. A prior fix in version 1.5.1 was incomplete, and an additional attack vector remained exploitable until version 1.5.2, where script input was fully filtered. Successful exploitation can result in attacker-controlled expression evaluation on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a deliberately vulnerable training environment with working command-execution examples documented in app/README.md and its Chinese translation, rather than a standalone exploit client. The MVEL example reaches Runtime.exec directly through a script:: expression in nested request filters; the OGNL example uses reflective method selection through a personalization condition's propertyName. Both POST JSON to /context.json and execute hardcoded touch commands. No reverse-shell payload, command-output retrieval, persistence, exfiltration, or attacker callback endpoint is supplied. The 36-file repository contains vendored Vulhub material in app/, the historical Unomi image recipe and startup script in base/, derived service images in build/, a benign context health check in checks/, and the central Isoloom deployment specification in isoloom.yml. Generated .isoloom/ outputs support Docker Compose, Kubernetes, a Vagrant-hosted Docker VM, Proxmox, and six cloud providers: AWS, Azure, DigitalOcean, GCP, Linode, and OCI. GitHub workflows validate generated artifacts, run lab health checks, and conditionally publish the lab using secret-supplied service URLs. The code-file count of 19 comprises eight shell scripts, seven Terraform files, one Ruby Vagrantfile, and three Dockerfiles; YAML deployment and workflow files are additional configuration with some embedded shell code. Unomi runs at 10.61.40.10 and Elasticsearch at 10.61.40.20 on the Docker lab subnet 10.61.40.0/24. Generated Docker publishing defaults to loopback with dynamically allocated host ports unless fixed publishing is requested. VM/cloud provisioning binds published ports on all interfaces; cloud firewall rules restrict inbound SSH and application ports to an operator-supplied CIDR. Kubernetes exposes the application through a LoadBalancer and permits ingress to ports 8181 and 9443 from any IP. Elasticsearch remains an internal backend. Existing checks establish service readiness, authenticated REST API behavior, and successful benign context responses; they do not prove exploitability. Metadata identifies CVE-2020-13942 as a bypass of the CVE-2020-11975 fix. The English vendored guide says versions prior to 1.5.1, but the actual images and lab metadata explicitly select vulnerable 1.5.1; no broader affected-version range is established here. Cleanup commands in CI and VM provisioning have an infrastructure purpose and are not evidence of a fake exploit. Isoloom is a deployment generator, not an exploit framework. The analyzed repository's original URL, revision, and archive size were not supplied, so the repository fields use empty strings and zero as unavailable-value placeholders. The separately documented Vulhub upstream revision is 8fd63916f7a8711e2e01dda0d27237e4d6175d38. Findings are based on static inspection, not execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Apache Unomi explicitly listed among Sysrv's exploits.
A remote code execution vulnerability in Apache Unomi listed as one of Sysrv's exploits.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.