billow icon indicating copy to clipboard operation
billow copied to clipboard

OGNL Expression Injection Vulnerability

Open QiAnXinCodeSafe opened this issue 5 years ago • 0 comments

Hi! I am a staff member of QiAnXin Code Guard. In our open source code detection project, I found a OGNL Expression Injection Vulnerability in "billow". The details are as follows: In the handleComplexSQS(), the parameters in the request are obtained by getQuery(params), 图片 and finally the listQueuesFromQueryExpression() is passed in, followed by: 图片 Parsing the argument as an OGNL expression! An attacker can construct an OGNL expression for RCE

QiAnXinCodeSafe avatar May 06 '19 06:05 QiAnXinCodeSafe