{"id":"GHSA-wmfg-55f9-j8hq","summary":"Server-Side Template Injection","details":"### Impact\nA Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been assigned CVE-2020-26282.\n\n### Patches\nEffective Immediately, all users should upgrade to version 2.1.2 or higher.\n\n### Workarounds\nNone. \n\n### References\nhttps://securitylab.github.com/research/bean-validation-RCE\n\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the BrowserUp Proxy repo](http://github.com/browserup/browserup-proxy)\n* Contact us via  the [BrowserUp website](https://browserup.com) or email us at [support@browserup.com](mailto:support@browserup.com)","aliases":["CVE-2020-26282"],"modified":"2026-09-10T03:49:13.879483593Z","published":"2020-12-24T20:49:34Z","database_specific":{"github_reviewed_at":"2020-12-24T20:48:30Z","nvd_published_at":"2020-12-24T21:15:00Z","cwe_ids":["CWE-74"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/browserup/browserup-proxy/security/advisories/GHSA-wmfg-55f9-j8hq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26282"},{"type":"WEB","url":"https://github.com/browserup/browserup-proxy/commit/4b38e7a3e20917e5c3329d0d4e9590bed9d578ab"},{"type":"WEB","url":"https://github.com/browserup/browserup-proxy/releases/tag/v2.1.2"},{"type":"WEB","url":"https://securitylab.github.com/research/bean-validation-RCE"}],"affected":[{"package":{"name":"com.browserup:browserup-proxy","ecosystem":"Maven","purl":"pkg:maven/com.browserup/browserup-proxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.2"}]}],"versions":["1.1.0","1.2.0","1.2.1","2.0.0","2.0.1","2.1.0","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/12/GHSA-wmfg-55f9-j8hq/GHSA-wmfg-55f9-j8hq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}