Vulnerability Description
An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opennms | Opennms Horizon | < 26.1.0 |
| Opennms | Opennms Meridian | < 2018.1.19 |
Related Weaknesses (CWE)
References
- https://github.com/OpenNMS/opennms/releases/tag/opennms-26.0.1-1Release Notes
- https://issues.opennms.org/browse/NMS-12673Vendor Advisory
- https://www.opennms.com/en/blog/2020-04-29-opennms-horizon-26-0-1-luchador-releaRelease NotesVendor Advisory
- https://www.opennms.com/en/blog/2020-04-29-opennms-meridian-2018-1-18-wildfire-rRelease NotesVendor Advisory
- https://www.opennms.com/en/blog/2020-04-29-opennms-meridian-2019-1-6-europa-releRelease NotesVendor Advisory
- https://github.com/OpenNMS/opennms/releases/tag/opennms-26.0.1-1Release Notes
- https://issues.opennms.org/browse/NMS-12673Vendor Advisory
- https://www.opennms.com/en/blog/2020-04-29-opennms-horizon-26-0-1-luchador-releaRelease NotesVendor Advisory
- https://www.opennms.com/en/blog/2020-04-29-opennms-meridian-2018-1-18-wildfire-rRelease NotesVendor Advisory
- https://www.opennms.com/en/blog/2020-04-29-opennms-meridian-2019-1-6-europa-releRelease NotesVendor Advisory
FAQ
What is CVE-2020-12760?
CVE-2020-12760 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objec...
How severe is CVE-2020-12760?
CVE-2020-12760 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12760?
Check the references section above for vendor advisories and patch information. Affected products include: Opennms Opennms Horizon, Opennms Opennms Meridian.