Disable BeanShell Interpreter Remote Server Mode
Published Aug 17, 2023
8.8
HIGHCVSS 3.1
EPSS 0.78%
Description
A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code execution. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Affected products
-
- Version 29.0.4StatusaffectedConstraints<32.0.2
- Version
-
- Version 2020.0.0StatusaffectedConstraints<=2020.1.37
- Version 2021.0.0StatusaffectedConstraints<=2021.1.29
- Version 2022.0.0StatusaffectedConstraints<=2022.1.18
- Version 2023.0.0StatusaffectedConstraints<=2023.1.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The OpenNMS Group | Horizon | unaffected |
| |||||||||||||||
| The OpenNMS Group | Meridian | unaffected |
|
-
- Version 29.0.4StatusaffectedConstraints<32.0.2
- Version
-
- Version 2020.0.0StatusaffectedConstraints<=2020.1.37
- Version 2021.0.0StatusaffectedConstraints<=2021.1.29
- Version 2022.0.0StatusaffectedConstraints<=2022.1.18
- Version 2023.0.0StatusaffectedConstraints<=2023.1.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://docs.opennms.com/horizon/32/releasenotes/changelog.html Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2214 Advisory
- https://github.com/OpenNMS/opennms/commit/2909448b039bd46241efa52c450ffdb4f5a7dee1
- https://github.com/OpenNMS/opennms/pull/6368 Issue TrackingPatch
- https://github.com/advisories/GHSA-5m5f-qg8r-p9qf Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-40313
Change history (0)
No recorded changes yet.