CVE-2025-53192: Apache Commons OGNL: Expression Injection leading to RCE

Arnout Engelen <[email protected]> Mon, 18 Aug 2025 20:07:24 +0000
Newsgroups gmane.comp.jakarta.commons.user
Message-ID <[email protected]>
Severity: moderate=20

Affected versions:

- Apache Commons OGNL: all versions

Description:

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of =
Expression/Command Delimiters vulnerability in Apache Commons OGNL.

This issue affects Apache Commons OGNL: all versions.



When using the API Ognl.getValue=E2=80=8B, the OGNL engine parses and =
evaluates the provided expression with powerful capabilities, including =
accessing and invoking related methods,
 etc. Although OgnlRuntime attempts to restrict certain dangerous classes =
and methods (such as java.lang.Runtime) through a blocklist, these =
restrictions are not comprehensive.=20
Attackers may be able to bypass the restrictions by leveraging class =
objects that are not covered by the blocklist and potentially achieve =
arbitrary code execution.

As this project is retired, we do not plan to release a version that fixes =
this issue. Users are recommended to find an alternative or restrict access=
 to the instance to trusted users.


NOTE: This vulnerability only affects products that are no longer supported=
 by the maintainer.

Credit:

yyjLF (finder)

References:

https://commons.apache.org/
https://www.cve.org/CVERecord?id=3DCVE-2025-53192