{"id":"CVE-2020-11002","aliases":["GHSA-8jpx-m2wh-2v34"],"url":"https://o3.security/vulnerability/CVE-2020-11002","summary":"Remote Code Execution (RCE) vulnerability in dropwizard-validation","details":"dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability. If you are using a self-validating bean an upgrade to Dropwizard 1.3.21/2.0.3 or later is strongly recommended. The changes introduced in Dropwizard 1.3.19 and 2.0.2 for CVE-2020-5245 unfortunately did not fix the underlying issue completely. The issue has been fixed in dropwizard-validation 1.3.21 and 2.0.3 or later. We strongly recommend upgrading to one of these versions.","published":"2020-04-10T19:15:13.007Z","modified":"2026-07-08T20:58:30.184447Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"io.dropwizard:dropwizard-validation","fixedVersion":"1.3.21"},{"ecosystem":"Maven","name":"io.dropwizard:dropwizard-validation","fixedVersion":"2.0.3"}],"fix":{"url":"https://github.com/dropwizard/dropwizard/commit/d5a512f7abf965275f2a6b913ac4fe778e424242","label":"dropwizard/dropwizard@d5a512f"},"references":[{"type":"ADVISORY","url":"https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-hibernateconstraintvalidatorcontext"},{"type":"ADVISORY","url":"https://github.com/dropwizard/dropwizard/security/advisories/GHSA-8jpx-m2wh-2v34"},{"type":"ADVISORY","url":"https://github.com/dropwizard/dropwizard/security/policy#reporting-a-vulnerability"},{"type":"FIX","url":"https://github.com/dropwizard/dropwizard/commit/d5a512f7abf965275f2a6b913ac4fe778e424242"},{"type":"FIX","url":"https://github.com/dropwizard/dropwizard/pull/3208"},{"type":"FIX","url":"https://github.com/dropwizard/dropwizard/pull/3209"},{"type":"EVIDENCE","url":"https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:58:30.184447Z"}}