CVE-2020-13942
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedIt is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem. Source description excerpt; complete tracked detail loads below.
NVD published: Nov 24, 2020 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What is affected
ReportedApache — unomi. Product-level identification only; no affected-version conclusion is available from this field.
NVD published: Nov 24, 2020 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Urgency and basis
ReportedAct · 458.1
Tracker decision tier from the evidence detailed below · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Exploitation evidence
Reportedkev-listed · VulnCheck KEV
VulnCheck KEV added: Apr 12, 2021 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What to do
ReportedApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Tracked source remediation field · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Evidence detail
Loading the full tracker evidence record…