{"id":"GHSA-8jpx-m2wh-2v34","summary":"Remote Code Execution (RCE) vulnerability in dropwizard-validation","details":"### Summary\n\nA server-side template injection was identified in the self-validating ([`@SelfValidating`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/SelfValidating.html)) feature of **dropwizard-validation** enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability.\n\nIf you're using a self-validating bean (via [`@SelfValidating`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/SelfValidating.html)), an upgrade to Dropwizard 1.3.21/2.0.3 or later is strongly recommended.\n\nThe changes introduced in Dropwizard 1.3.19 and 2.0.2 (see [GHSA-3mcp-9wr4-cjqf](https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqf)/[CVE-2020-5245](https://github.com/advisories/GHSA-3mcp-9wr4-cjqf)) unfortunately didn't fix the underlying issue completely.\n\n### Impact\n\nThis issue may allow Remote Code Execution (RCE), allowing to run arbitrary code on the host system (with the privileges of the Dropwizard service account privileges) by injecting arbitrary [Java Expression Language (EL)](https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-interpolation-with-message-expressions) expressions when using the self-validating feature ([`@SelfValidating`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/SelfValidating.html), [`@SelfValidation`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/SelfValidation.html)) in **dropwizard-validation**.\n\n### Patches\n\nThe issue has been fixed in **dropwizard-validation** **1.3.21** and **2.0.3** or later. We strongly recommend upgrading to one of these versions.\n\nThe evaluation of EL expressions has been disabled by default now.\n\nIn order to use some interpolation in the violation messages added to [`ViolationCollector`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/ViolationCollector.html), it has to be explicitly allowed by setting [`SelfValidating#escapeExpressions()`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/SelfValidating.html#escapeExpressions--) to `false`.\n\nIt is also recommended to use the `addViolation` methods supporting message parameters instead of EL expressions introduced in Dropwizard 1.3.21 and 2.0.3:\n* [`ViolationCollector#addViolation(String, Map\u003cString, Object\u003e`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/ViolationCollector.html#addViolation-java.lang.String-java.util.Map-)\n* [`ViolationCollector#addViolation(String, String, Map\u003cString, Object\u003e`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/ViolationCollector.html#addViolation-java.lang.String-java.lang.String-java.util.Map-)\n* [`ViolationCollector#addViolation(String, String, Integer, Map\u003cString, Object\u003e`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/ViolationCollector.html#addViolation-java.lang.String-java.lang.Integer-java.lang.String-java.util.Map-)\n* [`ViolationCollector#addViolation(String, String, String, Map\u003cString, Object\u003e`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/ViolationCollector.html#addViolation-java.lang.String-java.lang.String-java.lang.String-java.util.Map-)\n\n\n### Workarounds\n\nIf you are not able to upgrade to one of the aforementioned versions of **dropwizard-validation** but still want to use the [`@SelfValidating`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.2/io/dropwizard/validation/selfvalidating/SelfValidating.html) feature, make sure to properly sanitize any message you're adding to the [`ViolationCollector`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/ViolationCollector.html) in the method annotated with [`@SelfValidation`](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/SelfValidation.html).\n\nExample:\n```java\n@SelfValidation\npublic void validateFullName(ViolationCollector col) {\n    if (fullName.contains(\"_\")) {\n        // Sanitize fullName variable by escaping relevant characters such as \"$\"\n        col.addViolation(\"Full name contains invalid characters:  \" + sanitizeJavaEl(fullName));\n    }\n}\n```\n\nSee also:\nhttps://github.com/dropwizard/dropwizard/blob/v2.0.3/dropwizard-validation/src/main/java/io/dropwizard/validation/InterpolationHelper.java\n\n### References\n\n* https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqf\n* https://github.com/dropwizard/dropwizard/pull/3208\n* https://github.com/dropwizard/dropwizard/pull/3209\n* https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-hibernateconstraintvalidatorcontext\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [dropwizard/dropwizard](https://github.com/dropwizard/dropwizard/issues/new)\n* Start a discussion on the [dropwizard-dev mailing list](https://groups.google.com/forum/#!forum/dropwizard-dev)\n\n### Security contact\n\nIf you want to responsibly disclose a security issue in Dropwizard or one of its official modules, please contact us via the published channels in our [security policy](https://github.com/dropwizard/dropwizard/security/policy):\n\nhttps://github.com/dropwizard/dropwizard/security/policy#reporting-a-vulnerability","aliases":["CVE-2020-11002"],"modified":"2026-02-04T02:54:30.702612Z","published":"2020-04-10T18:42:20Z","related":["CVE-2020-11002"],"database_specific":{"github_reviewed_at":"2020-04-10T18:37:22Z","nvd_published_at":null,"cwe_ids":["CWE-74"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/dropwizard/dropwizard/security/advisories/GHSA-3mcp-9wr4-cjqf"},{"type":"WEB","url":"https://github.com/dropwizard/dropwizard/security/advisories/GHSA-8jpx-m2wh-2v34"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11002"},{"type":"WEB","url":"https://github.com/dropwizard/dropwizard/pull/3208"},{"type":"WEB","url":"https://github.com/dropwizard/dropwizard/pull/3209"},{"type":"WEB","url":"https://github.com/dropwizard/dropwizard/commit/d5a512f7abf965275f2a6b913ac4fe778e424242"},{"type":"WEB","url":"https://docs.jboss.org/hibernate/validator/6.1/reference/en-US/html_single/#section-hibernateconstraintvalidatorcontext"},{"type":"WEB","url":"https://github.com/dropwizard/dropwizard/security/policy#reporting-a-vulnerability"}],"affected":[{"package":{"name":"io.dropwizard:dropwizard-validation","ecosystem":"Maven","purl":"pkg:maven/io.dropwizard/dropwizard-validation"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.21"}]}],"versions":["0.7.0","0.7.0-rc1","0.7.0-rc2","0.7.0-rc3","0.7.1","0.8.0","0.8.0-rc1","0.8.0-rc2","0.8.0-rc3","0.8.0-rc4","0.8.0-rc5","0.8.1","0.8.1-rc2","0.8.2","0.8.3","0.8.4","0.8.5","0.9.0","0.9.0-rc1","0.9.0-rc2","0.9.0-rc3","0.9.0-rc4","0.9.0-rc5","0.9.1","0.9.1-rc1","0.9.2","0.9.3","1.0.0","1.0.0-rc1","1.0.0-rc2","1.0.0-rc3","1.0.0-rc4","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.0-rc1","1.1.0-rc2","1.1.0-rc3","1.1.0-rc4","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.2.0","1.2.0-rc1","1.2.0-rc2","1.2.0-rc3","1.2.0-rc4","1.2.0-rc5","1.2.0-rc6","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.0","1.3.0-rc1","1.3.0-rc2","1.3.0-rc3","1.3.0-rc4","1.3.0-rc5","1.3.0-rc6","1.3.0-rc7","1.3.1","1.3.10","1.3.11","1.3.12","1.3.13","1.3.14","1.3.15","1.3.16","1.3.17","1.3.18","1.3.19","1.3.2","1.3.20","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-8jpx-m2wh-2v34/GHSA-8jpx-m2wh-2v34.json"}},{"package":{"name":"io.dropwizard:dropwizard-validation","ecosystem":"Maven","purl":"pkg:maven/io.dropwizard/dropwizard-validation"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.3"}]}],"versions":["2.0.0","2.0.1","2.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-8jpx-m2wh-2v34/GHSA-8jpx-m2wh-2v34.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}