{"id":"GHSA-w48j-pp7j-fj55","summary":"Valtimo scripting engine can be used to gain access to sensitive data or resources","details":"### Impact\nAny admin that can create or modify and execute process-definitions could gain access to sensitive data or resources.\n\nThis includes but is not limited to:\n- Running executables on the application host\n- Inspecting and extracting data from the host environment or application properties\n- Spring beans (application context, database pooling)\n\n### Attack requirements\nThe following conditions have to be met in order to perform this attack:\n- The user must be logged in\n- The user must have the admin role (ROLE_ADMIN), which is required to change process definitions\n- The user must have some knowledge about running scripts via a the Camunda/Operator engine\n\n### Patches\nVersion 12.16.0 and 13.1.2 have been patched. It is strongly advised to upgrade.\n\n### Workarounds\nIf no scripting is needed in any of the processes, it could be possible to disable it altogether via the `ProcessEngineConfiguration`:\n```\n@Component\nclass NoScriptEnginePlugin : ProcessEnginePlugin {\n    override fun preInit(processEngineConfiguration: ProcessEngineConfigurationImpl) {}\n\n    override fun postInit(processEngineConfiguration: ProcessEngineConfigurationImpl) {\n        processEngineConfiguration.scriptEngineResolver = null\n    }\n\n    override fun postProcessEngineBuild(processEngine: ProcessEngine) {}\n}\n```\nWarning: this workaround could lead to unexpected side-effects. Please test thoroughly.\n\n### References\n- Valtimo 12 and lower: [Camunda Scripting](https://docs.camunda.org/manual/latest/user-guide/process-engine/scripting/#custom-scriptengineresolver)\n- Valtimo 13 and higher: [Operaton Scripting](https://docs.operaton.org/docs/documentation/user-guide/process-engine/scripting)","aliases":["CVE-2025-58059"],"modified":"2026-09-10T03:50:27.693444630Z","published":"2025-08-28T16:46:10Z","database_specific":{"github_reviewed_at":"2025-08-28T16:46:10Z","nvd_published_at":"2025-08-28T18:15:33Z","cwe_ids":["CWE-200","CWE-78"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/valtimo-platform/valtimo-backend-libraries/security/advisories/GHSA-w48j-pp7j-fj55"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58059"},{"type":"WEB","url":"https://github.com/valtimo-platform/valtimo-backend-libraries/commit/45eb60b0b2df5964fb9917295d0dceb1fff8dd85"},{"type":"PACKAGE","url":"https://github.com/valtimo-platform/valtimo-backend-libraries"}],"affected":[{"package":{"name":"com.ritense.valtimo:core","ecosystem":"Maven","purl":"pkg:maven/com.ritense.valtimo/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.16.0.RELEASE"}]}],"versions":["0.0.0","0.0.0-test","0.1.0-RC-2","10.0.0.RELEASE","10.1.0.RELEASE","10.2.0.RELEASE","10.3.0.RELEASE","10.4.0.RELEASE","10.4.1.RELEASE","10.5.0.RELEASE","10.5.1.RELEASE","10.5.2.RELEASE","10.5.3.RELEASE","10.6.0.RELEASE","10.7.0.RELEASE","10.8.0.RELEASE","10.8.2.RELEASE","10.8.3.RELEASE","10.8.4.RELEASE","10.8.5.RELEASE","11.0.0.RELEASE","11.1.0.RELEASE","11.1.1.RELEASE","11.1.2.RELEASE","11.1.4.RELEASE","11.1.5.RELEASE","11.1.6.RELEASE","11.2.0.RELEASE","11.2.1.RELEASE","11.2.2.RELEASE","11.3.0.RELEASE","11.3.1.RELEASE","11.3.2.RELEASE","11.3.3.RELEASE","11.3.5.RELEASE","12.0.0.RELEASE","12.0.1.RELEASE","12.1.0.RELEASE","12.1.1.RELEASE","12.1.2.RELEASE","12.1.3.RELEASE","12.10.0.RELEASE","12.10.1.RELEASE","12.10.2.RELEASE","12.11.0.RELEASE","12.12.0.RELEASE","12.13.0.RELEASE","12.13.1.RELEASE","12.14.0.RELEASE","12.14.1.RELEASE","12.14.2.RELEASE","12.15.1.RELEASE","12.2.0.RELEASE","12.2.1.RELEASE","12.3.0.RELEASE","12.3.1.RELEASE","12.4.0.RELEASE","12.4.1.RELEASE","12.4.3.RELEASE","12.5.0.RELEASE","12.5.1.RELEASE","12.6.0.RELEASE","12.6.1.1.RC","12.6.1.RELEASE","12.7.0.RELEASE","12.7.1.RELEASE","12.7.2.RELEASE","12.7.3.RELEASE","12.8.0.RELEASE","12.9.0.RELEASE","9.1.0.RELEASE","9.10.0.RELEASE","9.11.0.RELEASE","9.12.0.RELEASE","9.13.0.RELEASE","9.14.0.RELEASE","9.15.0.RELEASE","9.15.1.RELEASE","9.16.0.RELEASE","9.17.0.RELEASE","9.18.0.RELEASE","9.19.0","9.2.0.RELEASE","9.20.0.RELEASE","9.21.0.RELEASE","9.22.0.RELEASE","9.23.0.RELEASE","9.24.0.RELEASE","9.25.0.RELEASE","9.26.0.RELEASE","9.26.1.RELEASE","9.26.2.RELEASE","9.3.1.RELEASE","9.4.0.RELEASE","9.5.0.RELEASE","9.6.0.RELEASE","9.6.1.RELEASE","9.7.0.RELEASE","9.7.1.RELEASE","9.8.0.RELEASE","9.9.0.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-w48j-pp7j-fj55/GHSA-w48j-pp7j-fj55.json"}},{"package":{"name":"com.ritense.valtimo:core","ecosystem":"Maven","purl":"pkg:maven/com.ritense.valtimo/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.0.0.RELEASE"},{"fixed":"13.1.2.RELEASE"}]}],"versions":["13.0.0.RELEASE","13.0.1.RELEASE","13.0.2.RELEASE","13.1.0.RELEASE","13.1.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-w48j-pp7j-fj55/GHSA-w48j-pp7j-fj55.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}