← Vulnerability feed

Vulnerability record · CVE-2020-5245 · published 24 February 2020

CVE-2020-5245: Dropwizard validation injection vulnerability

Dropwizard · Dropwizard Validation

Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.

8.8 CVSS 3.1 High EPSS 3.0% · top 13.1% CWE-74 · Injection
8.8CVSS 3.1 base score, v2 9.0
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://beanvalidation.org/2.0/spec/#validationapi-message-defaultmessageinterpolation Third Party Advisory
https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-interpolation-with-message-expressio Third Party Advisory
https://docs.oracle.com/javaee/7/tutorial/jsf-el.htm Third Party Advisory
https://github.com/dropwizard/dropwizard/commit/28479f743a9d0aab6d0e963fc07f3dd98e8c8236
https://github.com/dropwizard/dropwizard/commit/d87d1e4f8e20f6494c0232bf8560c961b46db634 PatchThird Party Advisory
https://github.com/dropwizard/dropwizard/pull/3157 PatchThird Party Advisory
https://github.com/dropwizard/dropwizard/pull/3160 PatchThird Party Advisory
https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqf ExploitThird Party Advisory
https://beanvalidation.org/2.0/spec/#validationapi-message-defaultmessageinterpolation Third Party Advisory
https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-interpolation-with-message-expressio Third Party Advisory
https://docs.oracle.com/javaee/7/tutorial/jsf-el.htm Third Party Advisory
https://github.com/dropwizard/dropwizard/commit/28479f743a9d0aab6d0e963fc07f3dd98e8c8236
https://github.com/dropwizard/dropwizard/commit/d87d1e4f8e20f6494c0232bf8560c961b46db634 PatchThird Party Advisory
https://github.com/dropwizard/dropwizard/pull/3157 PatchThird Party Advisory
https://github.com/dropwizard/dropwizard/pull/3160 PatchThird Party Advisory
https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqf ExploitThird Party Advisory

Track CVE-2020-5245 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed8.8CVE-2020-11002Dropwizard validation injection vulnerabilitydropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in …EPSS 5.2%8.3CVE-2021-2351Oracle advanced networking option broken cryptographic algorithm vulnerabilityVulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and …EPSS 2.4%8.1CVE-2020-36183Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.…EPSS 4.9%8.1CVE-2020-36179Netapp cloud backup deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common…EPSS 17%8.1CVE-2020-36180Netapp cloud backup deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…EPSS 4.0%8.1CVE-2020-36182Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…EPSS 4.0%8.1CVE-2020-36184Netapp cloud backup deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…EPSS 8.4%

Source: NIST National Vulnerability Database (record CVE-2020-5245), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.